Summary: ASUS has announced a critical security vulnerability, CVE-2025-2492, affecting certain routers with AiCloud enabled, allowing potential unauthorized function execution by remote attackers. With a CVSS score of 9.2, this flaw emphasizes the necessity for immediate firmware updates. ASUS recommends using strong, unique passwords and disabling vulnerable services if immediate patching is not feasible.
Affected: ASUS routers with AiCloud enabled
Keypoints :
- Critical flaw tracked as CVE-2025-2492 with a CVSS score of 9.2.
- Firmware updates available for multiple branches: 3.0.0.4_382, 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102.
- Recommendations include using strong, unique passwords and disabling AiCloud if immediate updates aren’t possible.
Source: https://thehackernews.com/2025/04/asus-confirms-critical-flaw-in-aicloud.html