VulnerabilityAnalyzed
CVE-2025-59367
An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system.
CRITICAL 9.3EPSS 0.85%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more information.
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-288, CWE-306
- Affected
- asus/dsl-ac51 firmware · asus/dsl-n16 firmware · asus/dsl-ac750 firmware
- Source
- 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
References
- https://www.asus.com/security-advisoryVendor Advisory
- https://www.asus.com/security-advisoryVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.