ID

VAR-202511-2421


CVE

CVE-2025-59370


TITLE

ASUS Router command injection vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-29782

DESCRIPTION

A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information. ASUS Router is a router product and accompanying management application launched by ASUS, primarily used for wireless connectivity and management in home and enterprise networks

Trust: 1.44

sources: NVD: CVE-2025-59370 // CNVD: CNVD-2025-29782

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-29782

AFFECTED PRODUCTS

vendor:asusmodel:router 3.0.0.4 386scope: - version: -

Trust: 0.6

vendor:asusmodel:router 3.0.0.4 388scope: - version: -

Trust: 0.6

vendor:asusmodel:router 3.0.0.6 102scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-29782

CVSS

SEVERITY

CVSSV2

CVSSV3

54bf65a7-a193-42d2-b1ba-8e150d3c35e1: CVE-2025-59370
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-29782
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-29782
severity: HIGH
baseScore: 8.3
vectorString: AV:N/AC:L/AU:M/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2025-29782 // NVD: CVE-2025-59370

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.0

sources: NVD: CVE-2025-59370

PATCH

title:Patch for ASUS Router command injection vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/777136

Trust: 0.6

sources: CNVD: CNVD-2025-29782

EXTERNAL IDS

db:NVDid:CVE-2025-59370

Trust: 1.6

db:CNVDid:CNVD-2025-29782

Trust: 0.6

sources: CNVD: CNVD-2025-29782 // NVD: CVE-2025-59370

REFERENCES

url:https://www.asus.com/security-advisory/

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2025-59370

Trust: 0.6

sources: CNVD: CNVD-2025-29782 // NVD: CVE-2025-59370

SOURCES

db:CNVDid:CNVD-2025-29782
db:NVDid:CVE-2025-59370

LAST UPDATE DATE

2025-12-19T23:03:06.080000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-29782date:2025-12-03T00:00:00
db:NVDid:CVE-2025-59370date:2025-11-25T22:16:16.690

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-29782date:2025-12-03T00:00:00
db:NVDid:CVE-2025-59370date:2025-11-25T08:15:52.810