High · published 2 June 2025 · last verified 17 August 2026

AyySSHush persistent SSH backdoor

Known vulnerabilities plus weak credentials were combined to add persistent SSH access that survives reboots.

Scope caveat: A reboot does not remove this class of persistent configuration change.

Affected products
ASUS consumer routers
Hardware revisions
Several consumer models
Firmware range
Pre-fix firmware builds
Threat
AyySSHush persistent SSH backdoor
CVE references
See CSA advisory
Impact
Known vulnerabilities plus weak credentials were combined to add persistent SSH access that survives reboots.
Conditions required
Exposed administration and unpatched firmware.
Vendor response
ASUS released firmware updates for supported models.
Consumer action
Install the latest ASUS firmware, inspect for unknown SSH keys or access, and replace unsupported models.
Status
Patched / investigate
Source type
Government