ASUS has released new firmware updates to address nine security vulnerabilities in its routers, including a critical authentication bypass flaw identified as CVE-2025-59366. This vulnerability affects routers with the AiCloud feature enabled, which allows remote access and personal cloud functionality. The flaw, stemming from an unintended side effect of the Samba functionality, could allow remote attackers to execute specific functions without proper authorization by chaining path traversal and OS command injection weaknesses. ASUS strongly urges all users to update their router firmware immediately to mitigate these risks.
For users with end-of-life ASUS router models that will not receive firmware updates, the company recommends disabling all internet-facing services such as AiCloud, WAN remote access, port forwarding, DDNS, VPN server, DMZ, port triggering, and FTP. Additionally, users are advised to use strong, unique passwords for both router login and WiFi to reduce exposure. The vulnerabilities have made outdated ASUS routers attractive targets for botnet campaigns, emphasizing the importance of prompt mitigation and firmware updates to protect against exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Alongside the patches, ASUS urged customers to immediately update firmware and advised owners of end-of-life models to disable AiCloud, remote access, port forwarding, and other internet-facing services. The company also recommended using strong passwords to reduce exposure.
ASUS disclosed and patched nine security flaws in its router firmware, including the critical authentication bypass CVE-2025-59366 affecting devices with AiCloud enabled. The fixes were released for firmware series 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.