What's new

ASUS GT-BE98-Pro Firmware version 3.0.0.6.102_39260 does not include the CVE-2025-15101 fix!

cc666

Very Senior Member
This is confirmed by Asus. Its a 8.5/10 on the security threat, why is the fix not availiable.

CC
 
... why is the fix not availiable.
Why ask here? Asus generally does not respond on this site. If you spoke to Asus, why not ask them. Wild speculation is they will release new firmware at some future time with the fix and indicate such (CVE patch) in the firmware release notes like they've done many times in the past.

 
Why ask here? Asus generally does not respond on this site. If you spoke to Asus, why not ask them. Wild speculation is they will release new firmware at some future time with the fix and indicate such (CVE patch) in the firmware release notes like they've done many times in the past.

My point being its a critical issue, they had firmware that fixed it but never released it. Seems no sense of urgency to me.

CC
 
My point being its a critical issue, they had firmware that fixed it but never released it. Seems no sense of urgency to me.

CC
Yes I can understand your concern. I asked my friend there and (quite quickly) the moderator on ZenTalk came and apologized. It is perfectly fine to post a firmware and remove it for whatever reason, but not so good practice to send an email out to update to a non-existent version/non-existent fix.

I did notice that for other models that I did receive emails for (this model is a tester for me and unregistered), that the firmware version to fix the CVE was already released a week or two prior to the email. Also I noticed that those release notes do not mention the specific CVE of concern. Only more/most recent Merlin firmware is still noting specific CVEs in the change log.
 
Those CSRF security flaws are not trivial to exploit. There is no real need to panic over them. You would need to be actively logged into the router webui at the same time that you access a malicious link that would then inject code into your logged webui.
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top