The router is the one device every other device on a network trusts without question. Every laptop, phone, printer, camera, and payment terminal sends its traffic through it, and whoever controls it can quietly watch that traffic, redirect it to fake login pages, or use the router as a hidden base from which to reach everything else. On October 1, 2026, ASUS disclosed two flaws in its router firmware that hand an attacker exactly that kind of control. One is rated critical, at 9.4 out of 10; the other is rated high, at 8.9.
These are not just home-user problems. ASUS routers are common in small offices, branch sites, shops, clinics, and the homes of staff who work remotely part of the week, places where a router tends to be set up once and then forgotten. The good news is that fixes are available and there are no reports of attacks yet. The less comfortable news is that ASUS routers have been hijacked by the thousands in recent years, almost always through known flaws on devices nobody got around to updating.
In plain terms: if ASUS routers carry any of your business traffic, update them now, while it is still a routine job rather than an incident.
How this came to light
ASUS published both vulnerabilities on October 1, 2026, acting as its own CVE Numbering Authority, with fixed firmware already available. The CVE records were reserved in late June, suggesting the issues were reported to ASUS over the summer, but neither record credits a researcher, and the public record does not say how they were found.
The two CVEs arrived alongside a third, unrelated fix: CVE-2026-93495, a high-severity (7.0) memory access flaw affecting 13 ASUS Z390 and C246 motherboards. That one requires physical access and a specially crafted device, so it is a much narrower risk, and the rest of this article focuses on the routers.
On October 1, CISA's enrichment of both router CVEs recorded exploitation as none, automatable as no, and technical impact as total. Neither appears in CISA's Known Exploited Vulnerabilities catalogue, and ASUS's advisory does not say whether the flaws have been used in attacks.
What are CVE-2026-14157 and CVE-2026-13313?
Both flaws are in the router's web management interface, the admin page used to configure the device, and both end with an attacker running commands on the router. They get there in very different ways.
CVE-2026-14157: a poisoned VPN profile
Many ASUS routers can act as a VPN client, so every device behind the router, including smart TVs and other hardware that cannot run VPN software itself, has its traffic routed through a VPN provider. Setting this up means downloading a configuration file from the provider, usually an OpenVPN .ovpn profile, and uploading it through the admin page. Newer firmware calls this feature VPN Fusion.
The flaw is in how the router reads that uploaded file. It is classed as CWE-134, use of an externally controlled format string: text inside the file that should be treated purely as data is instead interpreted as formatting instructions by the router's code. A carefully constructed file can abuse that to run arbitrary commands on the device.
Two details narrow the scope. The issue applies to configuration files imported into the router itself, not to VPN apps on a laptop or phone. And the upload has to happen through an authenticated admin session, so the attacker either already holds the admin password or persuades someone who does to import the file. ASUS's advisory warns directly that attackers may use social engineering to trick administrators, and tells owners to import VPN configuration files only from trusted sources.
CVE-2026-13313: debug code left switched on
The second flaw is a different kind of mistake, classed as CWE-489, active debug code. Functionality meant for development and troubleshooting remained reachable in production firmware. An authenticated attacker can send a crafted HTTP request to the admin interface that bypasses the router's security checks and switches on Telnet, an old, unencrypted remote access service, and then use it to run commands with root privileges. The CVE record notes that this can extend to other devices connected to the router.
Root on a router is total control: changing DNS settings to redirect traffic, capturing unencrypted data, installing persistent malware, opening new ways in, or using the router as a launch point against the internal network. This flaw also reaches further back than the VPN bug, covering two older firmware series as well as the current one.
Reading the scores
| CVE | CVSS v4.0 | Weakness | Trigger | Attack complexity | Privileges required |
|---|---|---|---|---|---|
| CVE-2026-14157 | 9.4 (Critical) | Format string (CWE-134) | Crafted VPN client file uploaded via admin page | Low | High |
| CVE-2026-13313 | 8.9 (High) | Active debug code (CWE-489) | Crafted HTTP request enabling Telnet | High | High |
Both scores are high despite requiring admin access, because both vectors rate the impact as high not only on the router but on the systems connected to it. That downstream impact is the point: the router is rarely the real target, it is the way in.
It would be a mistake to read "authentication required" as "low risk". Router admin passwords are often weak, left at defaults, reused, or shared among staff. Some owners expose the admin page to the internet for convenience. A router that was compromised previously may already have an attacker holding valid credentials. And the VPN flaw only needs one administrator to be talked into importing one file. Any of those turns a post-authentication bug into a practical one.
Who is affected?
ASUS identifies affected firmware by series rather than by model, so the advisory alone cannot tell you whether a particular router is exposed.
| CVE | Affected firmware series | Fix |
|---|---|---|
| CVE-2026-14157 | 3.0.0.6_102 | Latest firmware for your model |
| CVE-2026-13313 | 3.0.0.4_386, 3.0.0.4_388, 3.0.0.6_102 | Latest firmware for your model |
The firmware version is shown on the router's admin page. Compare it, along with the exact model, against the "Security Update for ASUS Router Firmware" section of the ASUS security advisory and the model's own support page.
A few points deserve attention:
- The VPN flaw only matters if the VPN client feature is used. Routers that never import VPN profiles are not exposed to CVE-2026-14157, though they may still be exposed to CVE-2026-13313.
- The Telnet flaw covers older firmware too. Including the 3.0.0.4_386 and 3.0.0.4_388 series widens the pool of affected hardware considerably.
- End-of-life routers will not be fixed. ASUS has said devices past end of life will not receive new firmware; its advice for those is limited to strong, unique admin and Wi-Fi passwords. Replacement is the durable answer.
Exploitation status: what we know
At the time of writing, no exploitation in the wild has been reported, no public proof-of-concept code has been reported, and EPSS estimates the probability of exploitation in the next 30 days at below 1% for each CVE. CISA's assessment that neither flaw is automatable reflects the authentication requirement: an attacker cannot simply scan the internet and compromise devices in bulk with these bugs alone.
The reason not to take too much comfort from that is history. ASUS routers have been a repeated target:
- CVE-2024-0401, disclosed by VulnCheck in 2024, was a command injection flaw triggered through the very same entry point: a crafted OpenVPN profile uploaded through the admin page. Two separate bugs in the same import path within about two years suggests the code behind this feature deserves continued scrutiny.
- The AyySSHush campaign, uncovered in 2025, combined authentication bypasses, brute-force logins, and a command injection flaw (CVE-2023-39780) to backdoor more than 9,000 ASUS routers, with persistence that survived firmware updates.
- A suspected Chinese espionage operation hijacked more than 50,000 ASUS home routers last year by exploiting known bugs in older and unsupported devices, folding them into a covert network used to disguise the origin of malicious traffic.
The AyySSHush case is the instructive one: brute-forced logins plus an authenticated command injection flaw is exactly the combination these two new CVEs would slot into. Disclosure is when the clock starts, not when it stops.
Why a home router is a business problem
For most organisations, the ASUS routers that matter are not in the server room. They are at a small branch, in a shop, or in a home office where a member of staff connects to company systems three days a week.
A compromised router on the same network as a work laptop is in a powerful position. It decides where the laptop's DNS lookups go, it sees traffic metadata, it can reach any service the laptop exposes to the local network, and it keeps that position across reboots and every software update the laptop receives. It is also almost always outside the organisation's visibility: no asset register entry, no logging, no monitoring, and no one responsible for patching it.
The controls that help are the ones that stop trusting the local network in the first place: an always-on VPN that routes work traffic to a firewall the organisation controls, a host firewall on work devices that denies inbound connections, and authenticated, encrypted connections to business services. None of these fixes the router, but all of them reduce what a compromised router is worth.
What should you do?
1. Find the ASUS routers you depend on
Identify ASUS routers at offices, branches, and, where policy allows, the homes of remote staff. Record the model and the firmware version shown on the admin page. A photograph of the label and the admin page's firmware screen is quicker than a form. A router that is not in an asset register is not being patched by anyone.
2. Update the firmware
Install the latest firmware for each model from ASUS's official support page, using the advisory to confirm the model is covered. Enable automatic firmware updates where the router supports them. If a model has reached end of life and will not receive the fix, plan its replacement now.
3. Close off the admin interface
Both flaws require reaching the admin page. Disable remote (WAN-side) web administration unless there is a clear business need, and if it must stay on, restrict it to specific trusted IP addresses. Confirm the setting rather than assuming the default. Removing that exposure removes most of the risk.
4. Strengthen admin credentials
Replace default, reused, or shared admin passwords with strong, unique ones. ASUS recommends at least 10 characters with a mix of uppercase letters, numbers, and symbols. Treat router admin credentials as privileged accounts, because that is what they are.
5. Only import VPN profiles directly from the provider
Never import a configuration file received by email, chat, a forum post, or from a well-meaning "helper". Download it directly from the VPN provider's own site. Anyone with router admin access should treat an unsolicited VPN file the way they would treat an unexpected invoice attachment.
6. Avoid untrusted scripts and tools on the local network
ASUS specifically advises against running scripts, tools, or commands from untrusted sources on devices inside the network, since these can interact with the router's admin page on an attacker's behalf.
Detection
Consumer routers rarely produce useful logs, so compromise is usually spotted through its side effects. What you can check:
- Telnet that nobody turned on. Check the router's administration settings for Telnet, and from inside the network check whether the router is listening on TCP port 23. An unexplained Telnet service is a strong indicator of tampering, given that enabling it is precisely what CVE-2026-13313 does.
- VPN client profiles nobody remembers creating, or recent changes to existing ones, on the VPN client or VPN Fusion page.
- Changed settings, particularly DNS server addresses, port forwarding rules, new administrative accounts, or remote access options that have been switched on.
- Unfamiliar admin logins in whatever access history the router keeps, especially from addresses outside the local network.
- Unusual outbound traffic from the router itself, which network monitoring upstream of the router may be able to see. Botnet infections tend to produce steady scanning or attack traffic.
- DNS anomalies on work devices, such as certificate warnings or familiar sites resolving to unexpected addresses.
If a router shows signs of compromise, do not simply update it. Disconnect it, reset it to factory defaults, install the latest firmware, set new admin and Wi-Fi passwords, and reconfigure it by hand rather than restoring a saved configuration. The AyySSHush backdoor survived firmware updates, so a clean reset matters. Then review the recent activity of devices that were connected to it, starting with any credentials typed over that network.
A note on the pattern
Neither of these flaws is exotic. A format string bug and debug code left in production are both well understood, well documented mistakes, and both live in the part of the router that is most exposed to the people using it: the admin page that parses files and requests from whoever is logged in. That this same VPN import path produced a serious bug in 2024 as well is a reminder that features which parse user-supplied files are where routers keep breaking.
The broader lesson is about ownership rather than ASUS. Routers at branch sites and in home offices carry business traffic, yet they rarely appear in an asset register, rarely have a named owner, and are patched only when someone happens to notice. The organisations that will handle this disclosure in an afternoon are the ones that already know which routers they depend on, who manages them, and when each one stops receiving updates.
Summary
| CVEs | CVE-2026-14157 and CVE-2026-13313 |
| Product | ASUS routers (affected by firmware series, not listed by model) |
| CVE-2026-14157 | Format string flaw (CWE-134) in VPN client file import; CVSS 9.4 (Critical); 3.0.0.6_102 series |
| CVE-2026-13313 | Active debug code (CWE-489) allowing Telnet to be enabled with root access; CVSS 8.9 (High); 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series |
| Attack requirements | Authenticated access to the router's web admin interface, or tricking an administrator |
| Impact | Arbitrary command execution on the router, up to root; potential impact on connected devices |
| Disclosed | October 1, 2026 (ASUS as CNA) |
| Exploited in the wild? | None reported; not in CISA KEV |
| CISA enrichment | Exploitation: none; automatable: no; technical impact: total |
| Public PoC? | None reported |
| Fix | Latest firmware for each affected model; end-of-life models will not be patched |
| Interim mitigations | Disable WAN-side admin access, strong unique admin password, import VPN files only from the provider |
| Detection | Unexpected Telnet (TCP 23), unknown VPN client profiles, changed DNS or forwarding settings, unfamiliar admin logins |
| Related | CVE-2026-93495 (ASUS Z390 and C246 motherboards, CVSS 7.0, physical access required) |
With fixes available and no reported attacks, this is a chance to act on your own schedule: find the ASUS routers your business relies on, update them, take their admin pages off the internet, and check that Telnet is off. History suggests that window will not stay open for long.
If you need help finding the routers that carry your business traffic across branch sites and remote staff, checking whether any of them have already been tampered with, or putting a process in place so the next router advisory is a routine job, get in touch. The device every other device trusts deserves to be on someone's list.