Skip to main content

Vendor archive

asus CVEs

Beta · best-effort

273 CVEs tagged to vendor asus49 Critical, 127 High, 94 Medium, 3 Low, 0 Unrated.

CVE-2022-22814

Published Mar 10, 2022

The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-22262

Published Mar 1, 2022

ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file access vulnerability. Since this function does not validate…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22054

Published Jan 14, 2022

ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated lo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46109

Published Jan 3, 2022

Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41289

Published Nov 15, 2021

ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a general user’s permission, local attackers can modify the BI…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40981

Published Sep 27, 2021

ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib director…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28686

Published Apr 8, 2021

AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enable low-privileged users to ach…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28685

Published Apr 8, 2021

AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 273 CVEsPage 4 of 11