CVE-2025-15101 PUBLISHED

Assigner: ASUS
Reserved: 26.12.2025 Published: 26.03.2026 Updated: 26.03.2026

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Web management interface of certain ASUS router models. This vulnerability potentially allows actions to be performed with the existing privileges of an authenticated user on the affected device, including the ability to execute system commands through unintended mechanisms. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor ASUS
Product Router
Versions Default: unaffected
  • Version 3.0.0.6_102 is affected

Credits

  • Per Idenfeldt Okuyama at CYLOQ reporter

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE
  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE