References https://www.twcert.org.tw/tw/cp-132-7859-0e104-1.html https://censys.com/blog/june-20-improper-authentication-vulnerability-in-asus-routers/ https://nvd.nist.gov/vuln/detail/CVE-2024-3080 https://www.asus.com/security-advisory/ https://www.csoonline.com/article/3966073/asus-patches-critical-router-flaw-that-allows-remote-attacks.html https://thehackernews.com/2025/04/asus-confirms-critical-flaw-in-aicloud.html https://securityaffairs.com/176697/security/asus-warns-of-a-router-authentication-bypass-flaw.html https://nvd.nist.gov/vuln/detail/CVE-2025-2492 https://www.bleepingcomputer.com/news/security/asus-warns-of-critical-auth-bypass-flaw-in-dsl-series-routers/
Related VulnerabilitiesPoCCVE-2026-49468: LiteLLM Proxy < 1.84.0 - Host Header Authentication BypassPoCCVE-2026-56681: 9router <=0.5.4 - Authentication BypassPoCCVE-2026-86218: N-able N-central <2026.3.1.14 - Pre-Authentication Remote Code ExecutionPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-0650: OpenFlagr <= 1.1.18 - Authentication BypassPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication BypassPoCCVE-2026-48558: SimpleHelp <=5.5.15 - OIDC JWT Authentication BypassPoCCVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication BypassPoCCVE-2026-86207: N-able N-central - Authentication Bypass