CVE Tools

Router

37 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Router, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Router CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Router CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-012
2025-020
2025-030
2025-045
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-1110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-060
2026-072
2026-081
2026-090

Severity

How the 37 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical414%
  • High1968%
  • Medium518%

Latest CVEs

The 15 most recently published vulnerabilities affecting Router.

  1. CVE-2026-75985TRENDnet Router ping.cgi command injection7.4
  2. CVE-2026-13385An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execut...—
  3. CVE-2026-11851Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose co...—
  4. CVE-2025-15101An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted par...8.8
  5. CVE-2025-59372A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potenti...—
  6. CVE-2025-59371An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized acce...—
  7. CVE-2025-59370A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device e...—
  8. CVE-2025-59369A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary SQL queries, leading to unauthorized ...—
  9. CVE-2025-59368An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of t...—
  10. CVE-2025-12003A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device. Refer to the ' Security Update for ASUS Router ...—
  11. CVE-2025-59365A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the ...—
  12. CVE-2025-59366An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of spec...9.8
  13. CVE-2025-64347Apollo Router Improperly Enforces Renamed Access Control Directives7.5
  14. CVE-2025-64173Apollo Router Core: Access Control Bypass on Polymorphic Types7.5
  15. CVE-2025-2492An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to ...9.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store