{"status":200,"message":"OK","result":{"data":[{"id":3114,"title":"Security Update for ASUS FA507NV / FA507NU BIOS","type":"Security Bulletin","affectedProducts":"<div>FA507NV 318、FA507NU 318</div>","cve":"<div>CVE-2026-19398</div>","popUpContent":"<div>ASUS has released a security update for ASUS TUF Gaming A15 (FA507NV / FA507NU) and recommends</div>\n<div>updating to the latest BIOS version.<br>If an official BIOS update becomes required for your specific system, please submit a service request</div>\n<div>with your product Serial Number for further assistance.</div>\n<div>&nbsp;</div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-19398\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2026-19398</a><br>CVSS 4.0 Score：6.8 / Medium&nbsp;<br>AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N</div>","publishedDate":"1787813147093","updateDate":"1787796060000"},{"id":3109,"title":"Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin","type":"Security Bulletin","affectedProducts":"<div><span data-teams=\"true\">GPU Tweak III v2.1.1.7 and earlier; GPU Tweak II v2.4.0.0 and earlier; AI Suite 3 v2.1.2.0 and earlier; VGA.dll (component used by Armoury Crate) v0.0.7.8 and earlier</span></div>","cve":"<div><span data-teams=\"true\">CVE-2026-8917</span></div>","popUpContent":"<div>ASUS has released security updates for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and a component used by Armoury Crate, and recommends updating to the latest versions to ensure optimal protection.<br>This update addresses a security vulnerability in these products. If exploited, the issue could allow a local user to escalate privileges on the system.<br>ASUS strongly recommends that users update the affected software to the fixed versions listed below immediately.</div>\n<div>For GPU Tweak III, GPU Tweak II, and AI Suite 3, please download and install the applicable or latest version from the ASUS Support site. For Armoury Crate, the latest update can be received by opening the application and clicking \"Check for Updates\" in its update center.</div>\n<div><br><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8917\" rel=\"noopener noreferrer\">CVE-2026-8917</a></div>\n<div>CVSS 4.0 Score：8.4 / High</div>\n<div>AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</div>","publishedDate":"1786416860050","updateDate":"1786413720000"},{"id":3108,"title":"Security Update for Armoury Crate App","type":"Security Bulletin","affectedProducts":"<div>affect versions prior to V6.5.7.0</div>","cve":"<div>CVE-2026-16727</div>","popUpContent":"<div>\n<div><span style=\"font-size: 14pt;\">ASUS has released a Software Update for Armoury Crate, a system management software. This update includes important security updates, and ASUS strongly recommends that users update their Armoury Crate installation to the latest version.<br>This vulnerability affects Armoury Crate versions earlier than V6.5.7.0. ASUS has released Armoury Crate V6.5.7.0 to address this issue; versions V6.5.7.0 and later are not affected.<br>The latest Software Update can be received by opening Armoury Crate, in the \"Settings\" &gt; \"Update Center\" tab, and clicking \"Check for Updates\". Click \"Update\" on Armoury Crate if the new version is available.<br>This update specifically addresses the CVE-2026-16727 vulnerability.</span></div>\n</div>\n<div>&nbsp;</div>\n<div>\n<div><span style=\"font-size: 14pt;\"><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-16727\" rel=\"noopener noreferrer\">CVE-2026-16727</a></span></div>\n<div><span style=\"font-size: 14pt;\">CVSS 4.0 Score：7.3 / High</span><br><span style=\"font-size: 14pt;\">AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span></div>\n</div>","publishedDate":"1785397887223","updateDate":"1785376860000"},{"id":3106,"title":"End-of-Life Notice and Driver Update for Legacy ASUS Drivers ","type":"Security Bulletin","affectedProducts":"<div>GLCKIO2.sys</div>\n<div>ASIO.sys</div>\n<div>ASIO2.sys</div>","cve":"<div style=\"text-align: left;\">CVE-2019-25764<br>CVE-2022-4989<br>CVE-2022-4990</div>","popUpContent":"<div>A privilege escalation vulnerability has been identified affecting the following legacy drivers, which have reached End-of-Life (EOL) and are no longer maintained: GLCKIO2.sys, ASIO.sys, and ASIO2.sys. If exploited, this vulnerability could allow a local user to escalate privileges on an affected system. ASUS has replaced these drivers with ASIO3.sys, which resolves this vulnerability. Software updated to use ASIO3.sys v1.03.02 or later is not affected. ASUS recommends that users check whether a newer version of their installed ASUS software (e.g., Aura Sync, AI Suite 3) is available, and update to the latest version to ensure the affected legacy drivers are no longer in use.</div>\n<div>&nbsp;</div>\n<div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2019-25764\" rel=\"noopener noreferrer\">CVE-2019-25764</a><br>CVSS 4.0 Score：7.3 / High<br>AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</div>\n<div>&nbsp;</div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-4989\" rel=\"noopener noreferrer\">CVE-2022-4989</a><br>CVSS 4.0 Score：8.5 / High &nbsp;<br>AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</div>\n<div>&nbsp;</div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2022-4990\" rel=\"noopener noreferrer\">CVE-2022-4990</a><br>CVSS 4.0 Score：7.3 / High<br>AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</div>\n</div>","publishedDate":"1784248941790","updateDate":"1784267880000"},{"id":3105,"title":"Security Update for ASUS GameSDK","type":"Security Bulletin","affectedProducts":"<div>v1.0.5 and earlier</div>","cve":"<div>CVE-2026-8919</div>","popUpContent":"<div>\n<div>ASUS has released a security update for ASUS GameSDK and recommends updating to the latest version to ensure optimal protection.<br>This update addresses a security vulnerability in ASUS GameSDK. If exploited, the issue could lead to local user credential disclosure and data tampering, and may in some cases cause GameSDK to become temporarily unavailable.<br>ASUS strongly recommends that users update ASUS GameSDK to v1.0.6.0 or later immediately.</div>\n<div>To update:</div>\n<div>\n<ol>\n<li>Open the Armoury Crate application.</li>\n<li>Go to the \"Update Center\" tab.</li>\n<li>Click \"Check for Updates\" and wait for the scan to complete.</li>\n<li>If a new version of GameSDK is listed, click \"Update\" next to it to install the update.</li>\n<li>Restart the application if prompted to complete the update.</li>\n</ol>\n</div>\n</div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8919\" rel=\"noopener noreferrer\">CVE-2026-8919</a><br>CVSS 4.0 Score：7.2 / High<br>AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L</div>","publishedDate":"1784107925433","updateDate":"1784080800000"},{"id":3104,"title":"Security Update for Aura Wallpaper Service","type":"Security Bulletin","affectedProducts":"<div>v2.1.15.0 and earlier</div>","cve":"<div>CVE-2026-8920</div>","popUpContent":"<div>ASUS has released a security update for Aura Wallpaper Service and recommends updating to the latest version to ensure optimal protection.<br>This update addresses a security vulnerability in Aura Wallpaper Service. If exploited, the issue could allow a local user to perform unauthorized file operations. On specific models, this may also cause a single feature to become unavailable.<br>ASUS strongly recommends that users update Aura Wallpaper to v2.2.2.0 or later immediately. The latest Software Update can be received by opening Armoury Crate, in the \"Settings\" &gt; \"Update Center\" tab, and clicking \"Check for Updates\". Click \"Update\" on Aura Wallpaper if the new version is available.<br><br><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8920\" rel=\"noopener noreferrer\">CVE-2026-8920</a><br>CVSS 4.0 Score：8.5 / High<br>AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N</div>","publishedDate":"1784107238407","updateDate":"1784080800000"},{"id":3101,"title":"Security Update for ASUS System Control Interface","type":"Security Bulletin","affectedProducts":"<div>ASUS System Control Interface v3 earlier than v3.1.66.0<br>ASUS System Control Interface earlier than v1.1.40.0<br>ASUS Business Manager earlier than v3.0.38.0&nbsp;</div>","cve":"<div>CVE-2026-15029</div>\n<div>CVE-2026-15030</div>\n<div>CVE-2026-13585</div>","popUpContent":"<div>ASUS has released important security updates for ASUS System Control Interface, the service used by the MyASUS app, and for ASUS Business Manager.&nbsp;This update applies to all personal computers, including desktops, laptops, NUCs, and All-in-One PCs.</div>\n<div>This update addresses security vulnerabilities related to improper access control within specific driver components of these products. If exploited, the issues could allow a local administrator to bypass intended security restrictions, potentially impacting system integrity.</div>\n<div>ASUS strongly recommends that users update to the latest version immediately.&nbsp;</div>\n<div><span data-teams=\"true\">For ASUS System Control Interface, the update can be received via the MyASUS app (with an internet connection), the ASUS Support website, or Windows Update. For ASUS Business Manager, the update can be received via the MyASUS app or the ASUS Support website.</span></div>\n<div>&nbsp;</div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-15029\" rel=\"noopener noreferrer\">CVE-2026-15029</a><br>CVSS 4.0 Score：8.4 / High<br>AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</div>\n<div>&nbsp;</div>\n<div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-15030\" rel=\"noopener noreferrer\">CVE-2026-15030</a><br>CVSS 4.0 Score：5.6 / Medium<br>AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</div>\n<div>&nbsp;</div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-13585\" rel=\"noopener noreferrer\">CVE-2026-13585</a><br>CVSS 4.0 Score：8.2 / High<br>AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:N/SA:H</div>\n</div>","publishedDate":"1784084298460","updateDate":"1784080740000"},{"id":3102,"title":"Security Update for ASUS Router Firmware","type":"Security Bulletin","affectedProducts":"<div>3.0.0.4_386 series</div>\n<div>3.0.0.4_388 series</div>\n<div>3.0.0.6_102 series</div>","cve":"<div>CVE-2026-13385</div>","popUpContent":"<div>ASUS has released a security update for ASUS routers to mitigate a reported vulnerability and strongly recommends updating to the latest firmware version to ensure optimal protection.<br>An improper certificate validation vulnerability exists in the UU feature of CN SKU ASUSWRT firmware. This vulnerability may allow a remote man-in-the-middle (MITM) user to make the router download and execute arbitrary commands via a spoofed server.<br>This issue affects only CN SKU models using the UU feature on ASUSWRT firmware 3.0.0.4_386 series, 3.0.0.4_388 series, and 3.0.0.6_102 series. Other regions are not affected.</div>\n<div>&nbsp;</div>\n<div><strong>Recommended Customer Action</strong><br>To protect your devices, ASUS strongly recommends that users of affected CN SKU models update their router firmware to the latest version available on the ASUS official website immediately.<br>You can find the latest firmware on the ASUS Support page at https://www.asus.com/support/ or the relevant product page at <a href=\"https://www.asus.com/Networking/\" rel=\"noopener noreferrer\">https://www.asus.com/Networking/</a><br>For End-of-Life (EOL) models unsupported by new firmware, users can mitigate this vulnerability by disabling the UU feature. Please refer to the ASUS EOL product list at <a href=\"https://www.asus.com/event/network/eol-product/\" rel=\"noopener noreferrer\">https://www.asus.com/event/network/eol-product/</a></div>\n<div>&nbsp;</div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-13385\" rel=\"noopener noreferrer\">CVE-2026-13385</a><br>CVSS 4.0 Score：9.5 / Critical<br>AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</div>","publishedDate":"1784083643997","updateDate":"1784080500000"},{"id":3103,"title":"Security Update for ASUS Router Firmware","type":"Security Bulletin","affectedProducts":"<div>3.0.0.4_386 series<br>3.0.0.4_388 series<br>3.0.0.6_102 series</div>","cve":"<div>CVE-2026-11851</div>","popUpContent":"<div>ASUS has released security updates for ASUS router firmware to address a reported vulnerability and recommends updating to the latest firmware version to ensure optimal protection.</div>\n<div>A vulnerability in the web management interface of certain ASUS router models may allow a remote authenticated user to disclose information through a crafted request that bypasses existing input validation.</div>\n<div>To protect your devices, ASUS recommends that all users update their router firmware to the latest version immediately.</div>\n<div>You can find the latest firmware on the ASUS Support page at (https://www.asus.com/support/) or the relevant product page at (https://www.asus.com/Networking/)</div>\n<div>&nbsp;</div>\n<div><strong>Mitigation</strong></div>\n<div>ASUS recommends applying the latest firmware update as the primary mitigation.</div>\n<div>If you cannot update immediately, ASUS recommends the following actions to reduce risk:</div>\n<div>* Disable Traffic Analyzer or Adaptive QoS until the firmware update is applied.<br>* Ensure the router administrator password and WiFi passwords are strong and unique.<br>* Keep the router web management interface accessible only from trusted local networks.<br>* Disable services accessible from the internet, including remote access from WAN, port forwarding, DDNS, VPN server, DMZ, port triggering, and FTP.<br>* Sign out active router management sessions and sign in again after updating firmware.</div>\n<div>&nbsp;</div>\n<div><strong>EOL Guidance</strong></div>\n<div>For End-of-Life (EOL) models unsupported by firmware versions released after March 2026, ASUS recommends replacing the device with a supported model. If continued use is unavoidable, ensure that both your router login and WiFi passwords are strong and unique, keep the web management interface accessible only from trusted local networks, and disable services accessible from the internet.</div>\n<div>&nbsp;</div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-11851\" rel=\"noopener noreferrer\">CVE-2026-11851</a><br>CVSS 4.0 Score：5.9 / Medium<br>AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</div>","publishedDate":"1784080479363","updateDate":"1785833520000"},{"id":3100,"title":"Security Update for ASUS Business Manager","type":"Security Bulletin","affectedProducts":"<div>Refer to the Security Update for ASUS Business Manager</div>","cve":"<div>CVE-2026-8921</div>","popUpContent":"<div>ASUS has released a security update for ASUS Business Manager to address an External Control of File Name or Path vulnerability.This vulnerability could allow a local user to execute arbitrary code with elevated privileges.<br>We advise you to review your equipment and security procedures regularly to maintain optimal system integrity. For users of ASUS commercial devices, we recommend taking the following steps: Update your software to the latest version. You can find the latest version<strong> (V3.0.41.0 or later)</strong> on the ASUS support page at <a href=\"https://www.asus.com/support/\" rel=\"noopener noreferrer\">https://www.asus.com/support/</a> or via MyASUS / Windows Update.</div>\n<div>&nbsp;</div>\n<div><strong>The following models running ASUS Business Manager version 3.0.38.0 or earlier are affected：</strong></div>\n<div>B5402CBAW, P1412CEA, P1512CEA, B1400CBA, B1500CBA, B5402FEA, B5402CEA, B5402CEAW, B1400CEPEY, B1500CEAEY, B1500CEPEY, B1400CEAEY, B1400CEAES, B1400CEPES, B1500CEAES, B1500CEPES, B9400CEAS, B7402FEA, B3402FEA, B3302FEA, B3302CEA, B1400CEAE, B1400CEPE, B1500CEAE, B1500CEPE, B9400CEAV, B9400CEA, BR1100CKA, BR1100FKA, L2402CYA, L2402FYA, L2502CYA, L2502FYA, L1400CDAY, D700MER, D500MER, D700SER, D500SER, S701TER, PD500TE, D700ME, D700SE, D500ME, D500SE, PD500TC, D900MC, D900SC, D700TC, D701TC, D700SC, D700MC, D500SC, S500MC, D500TC, X500MA, M5401WYA, M3200WYA, M3400WYA, M3700WYA, E1600WKA, E5202WHA, E5402WHA, M3400WUA, M3700WUA, A5401WRA, A5401WRP, V241EA, V241EP</div>\n<div>&nbsp;</div>\n<div>\n<div><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-8921\" rel=\"noopener noreferrer\">CVE-2026-8921</a></div>\n<div>CVSS 4.0 Score：8.5 / High<br>AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</div>\n</div>","publishedDate":"1783060774920","updateDate":"1783044060000"}],"pageNum":1,"totalSize":111}}