ASUS, a leading networking equipment manufacturer, has issued a critical security advisory for several router models.
The company has identified injection and execution vulnerabilities in certain firmware series that could allow authenticated attackers to trigger command execution through the ASUS router AiCloud feature.
The vulnerabilities CVE-2024-12912 and CVE-2024-13062 affect routers running firmware versions 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102.
If exploited, these flaws could enable authenticated administrators to execute arbitrary commands on the affected devices over the network, potentially compromising the security of entire home or business networks.
ASUS has released firmware updates for the affected series in response to these security risks. The company strongly urges all users to update their routers immediately to the latest firmware version available for their specific model.
To mitigate the risk, ASUS recommends users take the following steps:
ASUS emphasizes avoiding sequential numbers or letters in passwords, such as “1234567890” or “abcdefghij”.
This security advisory highlights the ongoing challenges in router security and the critical need for users to stay vigilant about firmware updates and best security practices.
As IoT devices become increasingly prevalent in homes and businesses, maintaining up-to-date firmware and strong security configurations is essential to protect against potential cyber threats.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
Microsoft has introduced Project Zenith, a new developer-optimized Windows 11 experience built for a class…
A financially motivated threat group known as Toy Ghouls has begun using two custom Windows…
NodeStealer has returned with a more invasive toolkit. The Python-based information stealer can now record…
Attackers are using invisible Unicode characters to make phishing emails appear harmless while disrupting the…
Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign…
Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users…