ASUS Removes File Shredder from Business Manager Amid Critical Security Flaw

Listen to this Post

Featured Image
ASUS has made a decisive move in response to a severe security vulnerability discovered in its Business Manager software. The company announced that it would completely discontinue the File Shredder feature rather than patch the flaw, highlighting the critical risk the functionality posed. This action emphasizes the growing need for organizations and users to remain vigilant about software updates and cybersecurity practices.

The vulnerability, identified as CVE-2025-13348, affected ASUS Business Manager version 3.0.36.0 and all earlier releases. Rather than offering a conventional patch, ASUS chose to remove the File Shredder feature entirely, eliminating the attack vector and preventing potential exploitation by malicious actors. This reflects both the severity of the flaw and the company’s commitment to user safety.

Updated versions of ASUS Business Manager no longer include the compromised feature, meaning users cannot accidentally expose their systems to the risk. The flaw impacted multiple versions of the software, making it critical for all users to upgrade immediately to versions later than 3.0.36.0. ASUS has made verification and updates available through their Security Advisory Portal at www.asus.com/securityadvisory
.

ASUS maintains an active role in global cybersecurity efforts as a CVE Numbering Authority (CNA) partner and member of FIRST (Forum of Incident Response and Security Teams). The company follows Coordinated Vulnerability Disclosure (CVD) best practices and aligns with ISO 29147:2018 and ISO 30111:2019 standards for vulnerability management. These practices underscore ASUS’s dedication to transparency and responsible security management.

This File Shredder vulnerability is part of ASUS’s broader security update cycle. Over 2025 and early 2026, the company released 89 security advisories covering various products, including MyASUS, router firmware, Armoury Crate, and UEFI firmware. The frequent updates illustrate the evolving cyber threat landscape and the necessity for users to maintain current software versions across all devices.

System administrators should verify that File Shredder is no longer present in their deployments and prioritize updating affected systems. Security teams are also advised to review logs and leverage endpoint detection and response (EDR) tools to determine if the vulnerability was previously exploited. Organizations dependent on file shredding should seek alternative solutions to ensure secure data deletion capabilities.

Regular monitoring of ASUS security advisories is crucial for staying ahead of emerging threats. Users and organizations are encouraged to adopt a proactive security posture, ensuring all software and firmware remain up to date to mitigate risks effectively.

What Undercode Say:

ASUS’s decision to remove the File Shredder feature rather than patch it is a rare but telling move in cybersecurity. Typically, companies issue targeted patches for vulnerabilities, but a complete removal signals the flaw was too severe to fix safely. This approach prioritizes risk elimination over feature retention, sending a strong message to organizations about the seriousness of maintaining strict security standards.

The vulnerability’s impact on multiple versions of Business Manager means many enterprises could have been exposed unknowingly. Organizations should not only update immediately but also audit historical system activity to detect any potential exploitation. The reliance on ISO-compliant processes and CVD protocols suggests ASUS is attempting to balance transparency with responsible risk mitigation.

Another notable takeaway is the trend of frequent updates and advisories from ASUS, with nearly 90 advisories in just over a year. This indicates that the threat landscape is rapidly evolving, and even widely used enterprise tools are vulnerable. IT teams must integrate these updates into routine security operations to reduce exposure.

The removal of a critical feature also underscores the trade-offs between usability and security. File shredding, while convenient, became a liability. Organizations dependent on this functionality now need to evaluate alternative secure deletion tools, reinforcing the principle that cybersecurity often requires operational flexibility.

Proactive monitoring and threat intelligence become essential. Enterprises should not wait for advisories to arrive passively but actively track vulnerabilities, test systems for exposure, and maintain strong EDR and logging practices. This incident also highlights that security is a moving target: features considered low-risk yesterday may present critical threats tomorrow.

Lastly, ASUS’s adherence to CNA and FIRST guidelines shows that even large vendors must follow structured disclosure processes. Organizations can use this as a benchmark for evaluating other vendor security practices and ensuring that their suppliers maintain rigorous vulnerability management protocols.

Fact Checker Results:

✅ CVE-2025-13348 is confirmed as a critical vulnerability affecting ASUS Business Manager 3.0.36.0 and earlier.

✅ ASUS officially removed the File Shredder feature rather than issuing a patch.

✅ Users are advised to update to newer versions via the official security advisory portal.

Prediction:

Given the severity of this flaw and ASUS’s removal of a key feature, we may see other hardware and software vendors take similar drastic measures for critical vulnerabilities in 2026. Enterprises could increasingly adopt alternative secure deletion tools, while IT teams will face heightened pressure to maintain rapid patching cycles. Expect security advisories from major vendors to increase, signaling a year of aggressive vulnerability mitigation. ✅📈

If you want, I can also create a concise infographic summarizing the vulnerability, impacted versions, and mitigation steps for quick reference in internal IT teams. This could make your advisory communications even more effective. Do you want me to do that?

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon