CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-59374

CVSS 9.3v4.0pub. 2025-12-17upd. 2025-12-18

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.

🤖 AI Analysis
How it works

Attackers modified official ASUS Live Update client distribution packages by introducing unauthorized code (CWE-506: embedded malware) before delivery to end users. Only devices meeting specific conditions (targeting mechanism) and having compromised versions installed were actually activated to execute unintended actions. ASUS Live Update client reached End-of-Support (EOS) status in October 2021 and is no longer supported by the manufacturer.

Impact

On devices meeting targeting conditions, attackers could cause unintended, unauthorized actions to be executed — the scope of impact depends on the functions of embedded malicious code. No currently supported ASUS devices or products are vulnerable to this issue.

Mitigation & patch

ASUS Live Update client reached End-of-Support status in October 2021 — the manufacturer will not release a patch for this application. All versions of ASUS Live Update client should be uninstalled and usage discontinued. To verify device status, refer to references published by ASUS at the address indicated in the manufacturer's references.

Who is affected

Selected versions of ASUS Live Update client (versions indicated in manufacturer's references), distributed before reaching End-of-Support status in October 2021. Currently supported ASUS devices and products are not affected by this issue.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Asus Live Update

    APP
    Asus
    < 3.6.8

CISA KEV — detailsi

Vendori
ASUS
Producti
Live Update
Added to KEVi
December 17, 2025
Remediation deadline (US Federal)i
January 7, 2026(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 7 stycznia 2026
CWE
References

Related vulnerabilities

CVE-2021-32030CRITICAL9.8⚠ KEVPL ✓same vendor

Authentication bypass w urządzeniach ASUS GT-AC2900 i Lyra Mini

CVE-2025-59367CRITICAL9.3PL ✓same vendor

Authentication bypass w routerach ASUS z serii DSL — nieautoryzowany dostęp zdalny

CVE-2023-5716CRITICAL9.8PL ✓same vendor

ASUS Armoury Crate — zapis i odczyt dowolnych plików przez sieć bez uwierzytelnienia

CVE-2023-47678CRITICAL9.1PL ✓same vendor

Nieprawidłowa kontrola dostępu w ASUS RT-AC87U — nieautoryzowany dostęp przez TFTP

CVE-2023-35087CRITICAL9.8PL ✓same vendor

Format string RCE w ASUS RT-AX56U V2 i RT-AC86U (AiMesh)