Router
37 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Router, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Router CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 2 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 5 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 10 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 37 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High19
- Medium5
Latest CVEs
The 15 most recently published vulnerabilities affecting Router.
- CVE-2026-75985TRENDnet Router ping.cgi command injection7.4
- CVE-2026-13385An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execut...—
- CVE-2026-11851Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose co...—
- CVE-2025-15101An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted par...8.8
- CVE-2025-59372A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potenti...—
- CVE-2025-59371An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized acce...—
- CVE-2025-59370A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device e...—
- CVE-2025-59369A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary SQL queries, leading to unauthorized ...—
- CVE-2025-59368An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of t...—
- CVE-2025-12003A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device. Refer to the ' Security Update for ASUS Router ...—
- CVE-2025-59365A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the ...—
- CVE-2025-59366An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of spec...9.8
- CVE-2025-64347Apollo Router Improperly Enforces Renamed Access Control Directives7.5
- CVE-2025-64173Apollo Router Core: Access Control Bypass on Polymorphic Types7.5
- CVE-2025-2492An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to ...9.4
Product grouping is registry-driven, with AI assist and human review. How it works