
SETROOTCERTIFICATE (write /etc/cert.pem.1) + APPLYAPP (RC_SERVICE execution). Refs: CVE-2025-2492, CVE-2024-12912, CVE-2025-59366; runZero; routersploit; ASUS advisory.
A Go program compiled with origasus.go, written for examining endpoints that can be associated with ASUS AiCloud / AsusWRT within the scope of authorized security testing or defense analysis (e.g., your own device, a pentest lab environment).
Important: The use of such software against unauthorized systems is illegal in most countries. Only run it with explicit permission and within a legal framework. Do not perform unauthorized scanning / exploitation in production or third-party networks.
The relevant references mentioned in the source file's header comments (e.g., CVE-2025-2492, CVE-2024-12912, CVE-2025-59366 and vendor advisories) can be used for security patches and risk assessment. The program's purpose is to enable security researchers and defense teams to recognize and mitigate this class of attacks; misuse is not supported.
In the project root:
go build -o origasus origasus.go
-f.exploited.txt (or the file specified with -exploited) and skipped on subsequent runs.Detailed request bodies, payload variants, and usage in production environments are outside the scope of this README; details are left only for source code review and authorized response processes.
Positional arguments: manual, no-skip, multiport, tls, debug (processed in main in the source).
Co-running with Zmap: zmap -p 443 | ./origasus
| Variable | Role |
|---|---|
ASUS_LOADER | Loader host (optional prefix in host:port format) |
ASUS_LOADER_PORT | Loader TCP port |
| / |
When SIGINT / SIGTERM is received, the process exits with code 124 (for external observers in long-running operations).
This software is provided "as is". The authors and contributors cannot be held liable for damages arising from unauthorized or illegal use. For defense-side use, rely on logs, network traces, and vendor security bulletins.
| Flag | Description |
|---|
-port | Connection port; null (from line host:port or separator with port), manual (443 + TLS), etc. |
-separator | Port separator in line (default: ,) |
-tls | Use TLS |
-multiport | Scan common port list for a single host |
-f | Input file (- or empty: stdin) |
-exploited | File holding processed hosts (default: exploited.txt) |
-no-skip | Do not skip previously flagged hosts |
ASUS_TAGASUS_PAYLOAD_ARG| Loader / tag parameter |