ASUS has released security updates to address a critical vulnerability in their AiCloud routers.
ASUS has released security updates to address a critical vulnerability (CVE-2025-59366) affecting AiCloud, a cloud-based remote-access feature in their routers. This vulnerability has a Common Vulnerability Scoring System (CVSSv3.1) score of 9.2 out of 10.
Successful exploitation of the authentication bypass vulnerability could allow an unauthenticated attacker to perform remote code execution.
The vulnerability affects the following product versions:
Users and administrators of affected products are advised to update firmware to the latest version immediately.
Users and administrators using End of Life (EOL) products are advised to upgrade their routers to a supported version to address the vulnerability. As a precaution, it is recommended to disable any services from being accessible to the internet, including:
Remote access from Wide Area Network (WAN)
Dynamic Domain Name System (DDNS)
Virtual Private Network (VPN) server
Demilitarised Zone (DMZ)
File Transfer Protocol (FTP)
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
