PT-2025-17288 · Asus · Asus Aicloud
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
ASUS AiCloud versions 3.0.0.4 3823, 0.0.4 3863, 0.0.4 388, and 3.0.0.6 102
Description
An improper authentication control issue exists in the AiCloud platform. This flaw allows a remote attacker to bypass authentication by using an alternative path or channel, potentially leading to the unauthorized execution of functions and the ability to execute arbitrary commands by sending specially crafted requests. The issue has been exploited by the Chinese APT actor UAT-7810 to establish Operational Relay Box (ORB) networks for secondary attacks.
Recommendations
Update the firmware of the affected versions to the latest available version.
As a temporary mitigation, disable AiCloud and all external access services.
Ensure the use of strong, unique passwords for networks and devices, incorporating uppercase letters, numbers, and symbols.
Fix
RCE
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Aicloud