CVE-2023-39780 and more on Asus routers

To all, informational

This is -for now- about NON OpenWrt devices Asus-RT-AX55, ASUS RT-AC3100 and/or RT-AC3200, but just to be aware:
If not known yet, as of 28 march this year, according https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers
Full info at https://www.labs.greynoise.io/grimoire/2025-03-28-ayysshush/
Asus routers could be infected by a SSH tcp/53282 backdoor hack.

Their recommendations:

  • Check ASUS routers for SSH access on TCP/53282.
  • Review the authorized_keys file for unauthorized entries.
  • Block the four IPs listed: 101.99.91.151, 101.99.94.173, 79.141.163.179, 111.90.146.237.
  • If compromise is suspected, perform a full factory reset and reconfigure manually.

Another reason to not use BCM devices? :slight_smile:
Although some ppl do try hard.

Regards, DGdodo.

1 Like