CVE-2025-15101Disclosure(asus / asus_firmware)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch asus asus_firmware systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted parameter. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.

2.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • asus_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-26); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
asus_firmware

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-26: 2Mentions · 2026-04-01: 2Mentions · 2026-04-08: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-15: 1Patch / Workaround · 2026-04-01: 2Technical Details · 2026-03-26: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-15: 103-2604-0104-0804-15
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure2
2026-04-012
Patch2
2026-04-081
General1
2026-04-151
Disclosure1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    ASUS issues a 8.5 CVSS patch for routers (CVE-2025-15101). A CSRF flaw lets attackers hijack sessions and change settings. Update your firmware today! #ASUS #RouterSecurity #CyberSecurity #InfoSec #PatchNow #Networking #CVE #HomeOffice #WiFiSecurity https://securityonline.info/asus-router-firmware-update-csrf-cve-2025-15101/ https://t.co/oKyEZCj7R2

    Post summary

    ASUS has released a firmware patch for CVE-2025-15101, a high‑severity CSRF flaw that could enable session hijacking; users are urged to update firmware promptly.

    02060575
    12.3K followersView on X
  • キタきつね@foxbook
    Patch

    ASUSがルーターの脆弱性に対するセキュリティパッチを公開 ASUS Issues Security Patch for Router Vulnerability #DailyCyberSecurity (Apr 1) https://securityonline.info/asus-router-firmware-update-csrf-cve-2025-15101/

    Post summary

    ASUS published a security patch for a router vulnerability (CVE‑2025‑15101). No evidence of exploitation, PoC, or technical depth is included in the snippet.

    00020422
    4.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15101 A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Web management interface of certain ASUS router models. This vulnerability potentially al… https://www.cve.org/CVERecord?id=CVE-2025-15101

    Post summary

    The post announces CVE-2025-15101 as a CSRF flaw in ASUS router web interfaces, but provides no PoC, exploit code, or patch details.

    00020177
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-15101 - ASUS Router CSRF Vulnerability Intel Report: https://ift.tt/8HLj73n

    Post summary

    Intel report announces CVE‑2025‑15101 as a CSRF flaw in ASUS routers, but does not provide PoC, exploit, active usage, or patch details.

    00010170
    285 followersView on X
  • Per Idenfeldt Okuyama@per__x
    Disclosure

    I wrote about three vulnerabilities that I found in ASUS router firmware, including the CVE-2025-15101 command injection. https://www.cyloq.se/research/cve-2025-15101-command-injection-in-asuswrt-firmware

    Post summary

    An author has identified a command injection vulnerability (CVE-2025-15101) in ASUS router firmware and documented it in a research article.

    00000266
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos ASUS ❗ CVE-2025-15101 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-asus-2/ https://t.co/y1ollqeqK5

    Post summary

    A brief notice identifies CVE-2025-15101 as affecting ASUS products and links to external source for more information, but provides no technical details, PoC, patch, or evidence of exploitation.

    00000384
    6.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSasusasus_firmware---

Explore more