ASUS vendor intelligence

ASUS Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting ASUS products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse ASUS KEVs Full KEV feed
Total KEVs
6
Known exploited vulnerabilities affecting ASUS products
In CISA KEV
3
Records also listed in the official catalog
Beyond CISA KEV
3
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
ASUS KEVs with sensor-observed exploitation activity

The catalog gap matters for ASUS exposure

Three of the six exploited ASUS CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss half of this vendor portfolio.

50%
Covered by CISA
50%
Beyond CISA
6
Product families

Attested ASUS CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2018-11511

The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the...

ADM High Beyond CISA 08 Dec 2025
CVE-2025-59374

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced...

live update Confirmed In CISA 01 Jun 2026
CVE-2023-39780

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist...

RT-AX55 Confirmed In CISA 01 Jun 2026
CVE-2021-32030

The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication...

GT-AC2900, Lyra Mini Confirmed In CISA 28 Apr 2025
CVE-2018-20334

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell...

ASUSWRT High Beyond CISA 20 Mar 2020
CVE-2013-5948

The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows...

RT-AC68U High Beyond CISA 21 Apr 2014

Showing 6 of 6 ASUS known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, authentication, and embedded malicious code account for five mapped occurrences across this ASUS KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.