PT-2025-48017 · Aicloud · Icloud
Nanyu Zhong
·
Published
2025-11-24
·
Updated
2025-12-09
·
CVE-2025-59366
CVSS v2.0
10
10
Critical
| Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AiCloud versions prior to 3.0.0.4 386/388/0.6 102
Description
An authentication bypass issue exists in AiCloud due to an unintended side effect of the Samba functionality. This allows execution of specific functions without proper authorization. The issue is described as a critical flaw with a CVSS score of 9.2. The vulnerability can be triggered through path traversal and OS command injection. There is no information available regarding the number of potentially affected devices worldwide or any real-world incidents where this issue was exploited. The vulnerability is related to the Samba functionality, which may involve the use of specific API Endpoints and the manipulation of parameters such as
file path or user credentials. The vulnerability allows unauthorized access to router functions.Recommendations
Update AiCloud to version 3.0.0.4 386/388/0.6 102 or later.
As a temporary workaround, consider disabling remote services to minimize the risk of exploitation.
Fix
RCE
Path traversal
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Related Identifiers
BDU:2025-15550
CVE-2025-59366
Affected Products
Icloud
References · 24
- https://bdu.fstec.ru/vul/2025-15550 · Security Note
- https://asus.com/content/security-advisory · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-59366 · Security Note
- https://twitter.com/stooee_/status/1997018229873488148 · Twitter Post
- https://twitter.com/catnap707/status/1993978755727937831 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1993664041659597012 · Twitter Post
- https://twitter.com/VulmonFeeds/status/1993258514442076206 · Twitter Post
- https://twitter.com/0dayPublishing/status/1993223153183494358 · Twitter Post
- https://reddit.com/r/Action1/comments/1piftm3/december_2025_patch_tuesday_overview · Reddit Post
- https://twitter.com/jbhall56/status/1993677023085269206 · Twitter Post
- https://twitter.com/offseq/status/1993243982491447569 · Twitter Post
- https://twitter.com/rfwaveio/status/1994777226382893366 · Twitter Post
- https://twitter.com/stooee_/status/1997380617189707802 · Twitter Post
- https://twitter.com/Karma_X_Inc/status/1993616593163633045 · Twitter Post
- https://twitter.com/stooee_/status/1996655842184056841 · Twitter Post