A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection Platforms. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Read More
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-59367

CVE-2025-59367: ASUS DSL-AC51 Auth Bypass Vulnerability

CVE-2025-59367 is an authentication bypass flaw in ASUS DSL-AC51 firmware that allows remote attackers to gain unauthorized access. This article covers the technical details, affected versions, security impact, and mitigation.

Updated: May 15, 2026

CVE-2025-59367 Overview

CVE-2025-59367 is an authentication bypass vulnerability affecting multiple ASUS DSL series routers. The flaw allows remote attackers to gain unauthorized access to the affected systems without valid credentials. ASUS has acknowledged the issue in its security advisory and released firmware updates for the impacted DSL router models.

The vulnerability is classified under [CWE-288] (Authentication Bypass Using an Alternate Path or Channel) and [CWE-306] (Missing Authentication for Critical Function). With a network-based attack vector requiring no user interaction or privileges, the issue presents a significant exposure for any DSL router reachable from the internet or untrusted networks.

Critical Impact

Remote, unauthenticated attackers can gain unauthorized administrative access to affected ASUS DSL routers, enabling traffic interception, configuration tampering, and pivoting into internal networks.

Affected Products

  • ASUS DSL-AC51 (router and firmware)
  • ASUS DSL-N16 (router and firmware)
  • ASUS DSL-AC750 (router and firmware)

Discovery Timeline

  • 2025-11-13 - CVE-2025-59367 published to NVD
  • 2026-02-06 - Last updated in NVD database

Technical Details for CVE-2025-59367

Vulnerability Analysis

The vulnerability allows attackers to bypass the authentication mechanism on the affected ASUS DSL series routers. The combination of [CWE-288] and [CWE-306] indicates that the device exposes a critical administrative function through a path that either does not require authentication or accepts authentication via an alternate channel that an attacker can reach without valid credentials.

Because the attack vector is network-based and requires no user interaction, an adversary only needs reachability to the router's management interface. Exposure increases when remote administration is enabled on the WAN interface, but adjacent attackers on the LAN or Wi-Fi can also reach the management plane.

Successful exploitation grants unauthorized access to the router's administrative functions. From there, attackers can modify DNS settings, alter firewall rules, enable remote access services, deploy persistent configurations, or use the device as a foothold for further network intrusion.

Root Cause

The root cause is missing or improperly enforced authentication on a critical function within the router's web management interface. The presence of [CWE-306] suggests that at least one administrative endpoint can be invoked without credential validation. The accompanying [CWE-288] mapping indicates that the issue may also involve an alternate path, such as a debug, recovery, or legacy interface, that circumvents the normal login flow.

Attack Vector

Attackers send crafted HTTP or HTTPS requests to the router's management interface over the network. No prior authentication, user interaction, or privileged position is required. ASUS has not published exploitation details, and no public proof-of-concept code is currently available. Refer to the ASUS Security Advisory for technical details on the affected endpoints and patch notes.

The vulnerability is described in prose only. No verified exploit code is available at this time.

Detection Methods for CVE-2025-59367

Indicators of Compromise

  • Unexpected changes to router DNS server configuration, firewall rules, or port forwarding entries.
  • New or modified administrative accounts on the router, or login events from unfamiliar source IP addresses.
  • Remote management or SSH/Telnet services enabled on the WAN interface when not previously configured.
  • Unusual outbound connections from the router to unknown command-and-control infrastructure.

Detection Strategies

  • Inspect router logs for administrative actions that lack a preceding successful authentication event.
  • Compare current firmware versions against the patched releases listed in the ASUS Security Advisory.
  • Scan internal and external networks for exposed management interfaces on affected DSL models.

Monitoring Recommendations

  • Forward router syslog data to a centralized logging or SIEM platform for correlation and retention.
  • Alert on configuration changes, firmware reflash events, and new administrative sessions on edge devices.
  • Monitor for anomalous DNS resolver settings on client devices that may indicate router-level redirection.

How to Mitigate CVE-2025-59367

Immediate Actions Required

  • Apply the latest firmware update for affected DSL-AC51, DSL-N16, and DSL-AC750 routers as published in the ASUS Security Advisory.
  • Disable remote (WAN-side) administration on all DSL routers until patching is confirmed.
  • Audit router configurations for unauthorized changes to DNS, firewall, and port forwarding settings.
  • Rotate administrative passwords and any pre-shared keys after patching.

Patch Information

ASUS has released firmware updates addressing this vulnerability for the affected DSL series routers. Administrators should consult the ASUS Security Advisory under the "Security Update for DSL Series Router" section to obtain the specific firmware versions and installation instructions for each model.

Workarounds

  • Restrict access to the router's management interface to trusted LAN hosts only.
  • Disable WAN-side HTTP, HTTPS, SSH, and Telnet administration where supported.
  • Place legacy or end-of-life DSL routers behind a separate firewall, or replace them with currently supported models.
bash
# Configuration example: restrict management to LAN only
# (Apply via the router's web UI under Administration > System)
Enable Web Access from WAN: No
Enable Telnet:              No
Enable SSH from WAN:        No
Allowed Management IPs:     <trusted internal subnet>

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechAsus

  • SeverityCRITICAL

  • CVSS Score9.3

  • EPSS Probability0.24%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-288

  • CWE-306
  • Vendor Resources
  • ASUS Security Advisory
  • Related CVEs
  • CVE-2025-3462: ASUS DriverHub Auth Bypass Vulnerability

  • CVE-2025-59366: ASUS AiCloud Auth Bypass Vulnerability

  • CVE-2025-2492: ASUS Router AiCloud Auth Bypass Flaw

  • CVE-2026-6737: ASUS AsusPTPFilter Privilege Escalation
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English