ASUS, a leading networking equipment manufacturer, has issued a critical security advisory for several router models.
The company has identified injection and execution vulnerabilities in certain firmware series that could allow authenticated attackers to trigger command execution through the ASUS router AiCloud feature.
The vulnerabilities CVE-2024-12912 and CVE-2024-13062 affect routers running firmware versions 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102.
If exploited, these flaws could enable authenticated administrators to execute arbitrary commands on the affected devices over the network, potentially compromising the security of entire home or business networks.
ASUS has released firmware updates for the affected series in response to these security risks. The company strongly urges all users to update their routers immediately to the latest firmware version available for their specific model.
To mitigate the risk, ASUS recommends users take the following steps:
ASUS emphasizes avoiding sequential numbers or letters in passwords, such as “1234567890” or “abcdefghij”.
This security advisory highlights the ongoing challenges in router security and the critical need for users to stay vigilant about firmware updates and best security practices.
As IoT devices become increasingly prevalent in homes and businesses, maintaining up-to-date firmware and strong security configurations is essential to protect against potential cyber threats.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…