China-Linked Operation “WrtHug” Hijacks Thousands of ASUS Routers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-39780 | Authenticated OS Command Injection in ASUS RT-AX55 Routers ASUS RT-AX55 routers contain an OS command injection vulnerability (CWE-78) that allows a remote, authenticated attacker to execute arbitrary operating-system commands on the device. The flaw is triggered when an authenticated session submits crafted input that the router passes to its underlying OS without proper sanitization, though the available data does not identify the specific vulnerable parameter or affected firmware versions. Successful exploitation yields arbitrary command execution at the router's privilege level, which an attacker could use to change device configuration, establish persistence, or pivot into the networks behind the router. Any deployed ASUS RT-AX55 router is affected per CISA's listing, with the greatest risk on units whose management interface is reachable remotely. CISA added the issue to the Known Exploited Vulnerabilities catalog on 2025-06-02 (noting it as represented by CVE-2023-41346), confirming exploitation in the wild; EPSS currently estimates a 33.9% probability of exploitation within 30 days (98th percentile), no public PoC is known, and ransomware use is unknown. Do: Update RT-AX55 firmware to the latest release from ASUS, checking the vendor's security advisory for CVE-2023-39780 and the related CVE-2023-41346, as the available data does not specify a fixed version. Until patched, restrict administrative access (disable WAN-side/remote management if not needed), enforce strong administrator credentials, and review device settings for signs of tampering. Federal agencies should apply vendor mitigations per BOD 22-01 timelines or discontinue use of affected RT-AX55 routers if mitigations are unavailable. | 8.8 | 40% | KEV PoC ×7 |
| largehundreds of thousands of units deployed worldwide, with tens of thousands to hundreds of thousands likely internet-exposed (estimate; no RT-AX55-specific… | |
| CVE-2023-41345 | ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system, or terminate services. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2024-12912 | An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. NVD description · AI analysis pending | 7.2 | 1% | — | — | ||
| CVE-2025-2492 | An improper authentication control vulnerability exists in AiCloud. An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. NVD description · AI analysis pending | 9.2 | 1% | — | — |
Full article382 words · extracted from infosecurity-magazine.com · click to collapse
A new China-linked threat campaign has already compromised thousands of ASUS WRT routers around the world in a bid to build a new espionage network, SecurityScorecard has warned.
The firm’s STRIKE team claimed in a new report today that Operation “WrtHug” exploits six mainly legacy vulnerabilities in order to gain elevated privileges on end-of-life SOHO devices.
These flaws – CVE-2023-41345, CVE-2023-41346, CVE-2023-41347, CVE-2023-41348, CVE-2024-12912, and CVE-2025-2492 – exploit the ASUS AiCloud service and OS injection vulnerabilities to enable persistence, the report noted.
Most of the infected devices also shared the same self-signed TLS certificate with an expiration date of 100 years.
“The STRIKE team first identified this global infrastructure campaign while researching a suspicious self-signed Transport Layer Security (TLS) certificate proliferating across thousands of devices with clusters of geographic targets,” the report noted.
“The campaign is not explicitly an ORB [operational relay box], but STRIKE assesses that it bears striking resemblance to other Chinese ORB and botnet operations.”
China the Likely Culprit
One of these operations was “AyySSHush,” a China-linked operation which also exploited CVE-2023-39780 to target end-of-life ASUS routers. In fact, SecurityScorecard claimed the threat actors behind both may be either the same entity, or at least collaborating.
Read more on ASUS threats: Thousands of ASUS Routers Hijacked in Stealthy Backdoor Campaign
Up to 50% of the victims in Operation WrtHug are located in Taiwan, adding another reason to suspect Chinese adversaries. The report also pointed to seven IPs with signs of compromise in both Operation WrtHug and AyySSHush.
“Due to this noticeable alignment with previous TTPs in ORB campaigns from Chinese advanced persistent threat (APT) actors, as well the geographical focus of the campaign, we assess with low-to-moderate confidence that Operation WrtHug is an ORB facilitation campaign from an unknown China-affiliated actor,” the report explained.
“This incident underscores the critical need for regular updates, vigilance against outdated services, and proactive monitoring to counter sophisticated, state-sponsored intrusion campaigns that continually evolve their tactics to achieve global espionage reach.”
SecurityScorecard security researcher, Gilad Maizles, added that the report also reveals a growing strategic interest from nation state groups in using consumer infrastructure as staging points for attacks.
“Operation WrtHug is a case study in how nation-state actors are embedding themselves in consumer infrastructure to build stealthy, resilient, global espionage networks,” he added.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/chinal-operation-wrthug-thousands/