“The backdoor is stored in non-volatile memory (NVRAM) and is therefore not removed during firmware upgrades or reboots.”
Nearly 9,000 ASUS routers have an attacker’s SSH key installed through ASUS’s own settings. Firmware updates do not remove it, so patching the CVE does nothing for routers already hit. Two of the auth bypasses used have no CVE at all. The only fix is a full factory reset.