CVE-2025-13348 - CVE House
Back to Database
Status published High CVE-2025-13348

An improper access control vulnerability exists in ASUS Secure Delete...

Vulnerability Description

An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local user sending a specially crafted request, potentially leading to the creation of arbitrary files in a specified path. Refer to the "Security Update for ASUS Business Manager" section on the ASUS Security Advisory for more information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13348

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ASUS Business Manager
Vulnerable Versions:
0

Timeline

Official Publish: February 2nd, 2026
Last Modified: February 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)