Threats Tagged 'cve-2025-13348'
View all threats tagged with 'cve-2025-13348'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-13348'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-13348 is a high-severity improper access control vulnerability in the ASUS Secure Delete Driver component of ASUS Business Manager. It allows a local attacker with limited privileges to send specially crafted requests that can lead to arbitrary file creation in specified paths without proper authorization. The vulnerability does not require user interaction and has a CVSS 4.0 score of 8.5, indicating significant impact on confidentiality, integrity, and availability. No known exploits are currently reported in the wild. This flaw could be leveraged to escalate privileges or persist on affected systems. European organizations using ASUS Business Manager, especially in sectors relying on ASUS hardware and software management tools, are at risk. Mitigation requires applying security updates from ASUS once available and restricting local user access to vulnerable components. Countries with higher ASUS market penetration and critical infrastructure using ASUS devices are more likely to be affected. Join the discussion | CVE Database V5 | 02/02/2026, 02:00:38 UTC Added: 02/02/2026, 02:12:48 UTC |
Showing 1 to 1 of 1 result