ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.
https://www.securityweek.com/over-50000-asus-routers-hacked-in-operation-wrthug/
https://www.theregister.com/2025/11/19/thousands_more_asus_routers_pwned/
https://www.infosecurity-magazine.com/news/chinal-operation-wrthug-thousands/
https://thehackernews.com/2025/11/wrthug-exploits-six-asus-wrt-flaws-to.html