"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
Attackers modified official ASUS Live Update client distribution packages by introducing unauthorized code (CWE-506: embedded malware) before delivery to end users. Only devices meeting specific conditions (targeting mechanism) and having compromised versions installed were actually activated to execute unintended actions. ASUS Live Update client reached End-of-Support (EOS) status in October 2021 and is no longer supported by the manufacturer.
On devices meeting targeting conditions, attackers could cause unintended, unauthorized actions to be executed — the scope of impact depends on the functions of embedded malicious code. No currently supported ASUS devices or products are vulnerable to this issue.
ASUS Live Update client reached End-of-Support status in October 2021 — the manufacturer will not release a patch for this application. All versions of ASUS Live Update client should be uninstalled and usage discontinued. To verify device status, refer to references published by ASUS at the address indicated in the manufacturer's references.
Selected versions of ASUS Live Update client (versions indicated in manufacturer's references), distributed before reaching End-of-Support status in October 2021. Currently supported ASUS devices and products are not affected by this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAsus Live Update
APPAsus< 3.6.8
CISA KEV — detailsi
- Vendori
- ASUS
- Producti
- Live Update
- Added to KEVi
- December 17, 2025
- Remediation deadline (US Federal)i
- January 7, 2026(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Related vulnerabilities
Authentication bypass w urządzeniach ASUS GT-AC2900 i Lyra Mini
Authentication bypass w routerach ASUS z serii DSL — nieautoryzowany dostęp zdalny
ASUS Armoury Crate — zapis i odczyt dowolnych plików przez sieć bez uwierzytelnienia
Nieprawidłowa kontrola dostępu w ASUS RT-AC87U — nieautoryzowany dostęp przez TFTP
Format string RCE w ASUS RT-AX56U V2 i RT-AC86U (AiMesh)