CVE-2025-13348Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local user sending a specially crafted request, potentially leading to the creation of arbitrary files in a specified path. Refer to the "Security Update for ASUS Business Manager" section on the ASUS Security Advisory for more information.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-02); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-02: 1Mentions · 2026-02-05: 1Mentions · 2026-02-10: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-10: 102-0202-0502-10
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-021
Disclosure1
2026-02-051
General1
2026-02-101
Patch1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Patch

    ASUS File Shredder がディスコン:脆弱性 CVE-2025-13348 の発見を受けて https://iototsecnews.jp/2026/02/03/asus-discontinues-file-shredder-feature-to-patch-critical-vulnerability/ この問題の原因は、ASUS Business Manager に搭載されていた “File Shredder” 機能に、システムの権限を不正に操作されるなどの、深刻な設計上の欠陥が含まれていたことにあります。この脆弱性 CVE-2025-13348 を悪用する攻撃者は、プログラムがファイルを完全に消去する際の処理プロセスに割り込むことが可能になります。ASUS は、この問題を単なるプログラムの書き換えで修正するのではなく、機能を完全に削除するという異例の対応を取りました。この措置は、File Shredder 機能の安全性を保ちながら維持することが、きわめて困難なほどの、根本的なリスクを抱えていたことを示しています。ご利用のチームは、ご注意ください。 #Asus #CVE202513348 #FileShredder #Vulnerability

    Post summary

    ASUS discontinued the File Shredder feature to patch CVE‑2025‑13348, a critical design flaw that could allow privilege escalation during file deletion; no active exploitation or PoC was reported.

    01000206
    483 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    ASUS Business ManagerのFile Shredder機能が削除に-脆弱性 CVE-2025-13348 対応で https://rocket-boys.co.jp/security-measures-lab/asus-business-managerfile-shredder-cve-2025-13348/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces a vulnerability (CVE‑2025‑13348) in ASUS Business Manager’s File Shredder function and references an external link, but it offers no further technical, exploit, or mitigation details.

    00000122
    318 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-13348 Local File Creation Vulnerability in ASUS Business Manager Secure Delete Driver https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-13348

    Post summary

    The text announces CVE-2025-13348, a local file creation vulnerability in ASUS Business Manager Secure Delete Driver, offering basic technical details but no PoC, exploit, or patch information.

    0000091
    4.0K followersView on X

Explore more