DriverHub Hijinks: Asus’s Pre-Installed Software Vulnerabilities Unveiled by MrBruh

DriverHub, pre-installed on Asus motherboards, had two vulnerabilities ripe for remote shenanigans, according to researcher MrBruh. These flaws, CVE-2025-3462 and CVE-2025-3463, could be exploited via crafted HTTP requests. Asus has patched these vulnerabilities, but MrBruh won’t be cashing in a bug bounty—just eternal glory in Asus’s “hall of fame.”

Pro Dashboard

Hot Take:

Who knew that updating your drivers could drive you straight into a hacker’s arms? DriverHub is like that overly enthusiastic friend who lets anyone join the party without checking IDs. Thanks to MrBruh, we now know that the only thing standing between our PCs and pandemonium was a flimsy “asus.com” disguise. But don’t worry, Asus has patched things up—just not with a bounty, but a shoutout in their “hall of fame.” Because who needs cash when you have virtual street cred?

Key Points:

  • DriverHub vulnerabilities, CVE-2025-3462 and CVE-2025-3463, can be exploited remotely for code execution.
  • The flaws stem from inadequate input validation and affect the software’s interaction and system behavior.
  • Only Asus motherboards with pre-installed DriverHub are vulnerable, not laptops or desktops.
  • MrBruh showed that modifying origin headers could bypass restrictions on RPC requests.
  • Asus issued fixes within a month, but no bug bounty was offered to MrBruh.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?