Cyber Security News

ASUS Routers Vulnerabilities Allows Arbitrary Code Execution

ASUS, a leading networking equipment manufacturer, has issued a critical security advisory for several router models.

The company has identified injection and execution vulnerabilities in certain firmware series that could allow authenticated attackers to trigger command execution through the ASUS router AiCloud feature.

The vulnerabilities CVE-2024-12912 and CVE-2024-13062 affect routers running firmware versions 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102.

If exploited, these flaws could enable authenticated administrators to execute arbitrary commands on the affected devices over the network, potentially compromising the security of entire home or business networks.

ASUS has released firmware updates for the affected series in response to these security risks. The company strongly urges all users to update their routers immediately to the latest firmware version available for their specific model.

To mitigate the risk, ASUS recommends users take the following steps:

  1. Update router firmware promptly when new versions become available. Users can find the latest firmware on the ASUS support page or their product’s specific page on the ASUS website.
  2. Implement strong, unique passwords for both the wireless network and router administration page. Passwords should be at least 10 characters long and include a mix of uppercase and lowercase letters, numbers, and symbols.
  3. Enable password protection within the AiCloud service.
  4. For users unable to update immediately or those with end-of-life routers running 3.0.0.4_382 firmware, ASUS advises:
    – Ensuring both login and WiFi passwords are strong
    – Disabling services accessible from the internet, such as remote access, port forwarding, DDNS, VPN server, DMZ, and FTP
  5. Regularly check and update security procedures and equipment.

ASUS emphasizes avoiding sequential numbers or letters in passwords, such as “1234567890” or “abcdefghij”.

This security advisory highlights the ongoing challenges in router security and the critical need for users to stay vigilant about firmware updates and best security practices.

As IoT devices become increasingly prevalent in homes and businesses, maintaining up-to-date firmware and strong security configurations is essential to protect against potential cyber threats.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Rajashekar Yasani

Rajashekar Yasani is a seasoned Cloud Security Engineer with extensive experience in cybersecurity research. As a security researcher, Rajashekar shares practical insights to help organizations enhance their security posture in an ever-evolving digital landscape.

Recent Posts

GitAuto Strengthens Code Security By Automating QA At Scale

In the current software landscape, security breaches caused by untested or poorly tested code are…

25 minutes ago

Cybersecurity in Mergers and Acquisitions – CISO Focus

Cybersecurity in mergers and acquisitions is crucial, as M&A activities represent key inflection points for…

2 hours ago

Top Cybersecurity Trends Every CISO Must Watch in 2025

In 2025, cybersecurity trends for CISOs will reflect a landscape that is more dynamic and…

2 hours ago

Zero Trust Architecture – A CISO’s Blueprint for Modern Security

Zero-trust architecture has become essential for securing operations in today’s hyper-connected world, where corporate network…

2 hours ago

Chrome 136 Released With Patch For 20-Year-Old Privacy Vulnerability

The Chrome team has officially promoted Chrome 136 to the stable channel for Windows, Mac,…

2 hours ago

SecAI Debuts at RSA 2025, Redefining Threat Investigation with AI

By fusing agentic AI and contextual threat intelligence, SecAI transforms investigation from a bottleneck into…

12 hours ago