ThreatCluster

New Vulnerabilities Identified in USB Network Drivers

First seen 18 Feb 2026, 15:24 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

Two new vulnerabilities have been reported in USB network drivers affecting devices using asix and aqc111 chipsets. CVE-2025-71094, published on January 13, 2026, addresses issues with PHY address validation, while CVE-2025-38153, published on July 3, 2025, focuses on error handling in usbnet read calls. Both vulnerabilities could impact the stability and security of affected systems.

Timeline

2025-07-03
CVE-2025-38153 published
2026-01-13
CVE-2025-71094 published
2026-02-18
Articles published regarding both vulnerabilities