<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — ASUS</title><description>Actively exploited vulnerabilities affecting ASUS products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/asus.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-59374 — ASUS Live Update Embedded Malicious Code Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-59374</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-59374</guid><description>ASUS Live Update was compromised in a supply chain attack, meaning attackers tampered with the software before it reached end users. Distributed builds contained embedded malicious code that could cause targeted devices to perform unintended actions. Because the threat was introduced at the distribution level, users who installed what appeared to be a legitimate update were exposed. The product is potentially end-of-life or end-of-service, making future patching unlikely and increasing the risk to anyone still running it.</description><pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate><category>ASUS</category><category>Live Update</category></item><item><title>CVE-2021-32030 — ASUS Routers Improper Authentication Vulnerability</title><link>https://wildfortech.com/security#CVE-2021-32030</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2021-32030</guid><description>This vulnerability in ASUS Lyra Mini and GT-AC2900 routers allows an attacker to bypass authentication and gain full access to the administrative interface — without valid credentials. For organizations running these devices, this means an attacker could reconfigure the router, intercept traffic, or use it as a pivot point into the broader network. CISA has flagged these products as potentially end-of-life or end-of-service, meaning patches may never arrive.</description><pubDate>Mon, 02 Jun 2025 00:00:00 GMT</pubDate><category>ASUS</category><category>Routers</category></item><item><title>CVE-2023-39780 — ASUS RT-AX55 Routers OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2023-39780</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2023-39780</guid><description>ASUS RT-AX55 routers contain an OS command injection flaw that lets a remote attacker who has valid credentials run arbitrary operating system commands on the device. Because routers sit at the network perimeter and control traffic flow, a compromised device can expose every connected system to interception, manipulation, or further attack. The vulnerability is tracked under both CVE-2023-39780 and CVE-2023-41346, indicating it has been confirmed serious enough for CISA to add to its Known Exploited Vulnerabilities catalog.</description><pubDate>Mon, 02 Jun 2025 00:00:00 GMT</pubDate><category>ASUS</category><category>RT-AX55 Routers</category></item></channel></rss>