CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-59367

CVSS 9.3v4.0pub. 2025-11-13upd. 2026-02-06

An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more information.

🤖 AI Analysis
How it works

The vulnerability results from flawed implementation of authentication mechanisms (CWE-288) or complete absence of required authentication for critical functions (CWE-306). A network attacker can bypass login procedures without needing any credentials, user interaction, or fulfillment of special conditions. The attack can be conducted remotely over the network, which significantly increases the risk of exploitation.

Impact

An attacker can gain unauthorized access to the router's management system, potentially allowing full control of the device, modification of network configuration, and enabling further attacks on devices in the local network.

Mitigation & patch

Apply patches available from the manufacturer according to the references — detailed information about firmware updates can be found in the ASUS Security Advisory message in the 'Security Update for DSL Series Router' section at https://www.asus.com/security-advisory

Who is affected

ASUS DSL-AC51, ASUS DSL-AC51 Firmware, ASUS DSL-N16, ASUS DSL-N16 Firmware, ASUS DSL-AC750 — specific firmware versions indicated in the manufacturer's references (ASUS Security Advisory, 'Security Update for DSL Series Router' section)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Asus Dsl Ac51

    HW
    Asus
    all versions
  • Asus Dsl Ac51 Firmware

    OS
    Asus
    < 1.1.2.3_1010
  • Asus Dsl Ac750

    HW
    Asus
    all versions
  • Asus Dsl Ac750 Firmware

    OS
    Asus
    < 1.1.2.3_1010
  • Asus Dsl N16

    HW
    Asus
    all versions
  • Asus Dsl N16 Firmware

    OS
    Asus
    < 1.1.2.3_1010
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2017-14698CRITICAL9.8PL ✓same product

ASUS DSL — zdalna zmiana hasła dowolnego użytkownika (Auth Bypass)

CVE-2017-14699MEDIUM6.5same product

Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC5...

CVE-2025-59374CRITICAL9.3⚠ KEVPL ✓same vendor

ASUS Live Update — kompromitacja łańcucha dostaw (supply chain compromise)

CVE-2021-32030CRITICAL9.8⚠ KEVPL ✓same vendor

Authentication bypass w urządzeniach ASUS GT-AC2900 i Lyra Mini

CVE-2023-5716CRITICAL9.8PL ✓same vendor

ASUS Armoury Crate — zapis i odczyt dowolnych plików przez sieć bez uwierzytelnienia