Skip to content
See the World Through ScienceA project of ALLATRA

ASUS Reports Two Router Flaws and Points Owners to a Firmware Update

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

An ASUS wireless router with its white case opened, showing the green circuit board inside and thin colored wires running to a small add-on board.
An ASUS wireless router opened on a workbench, with a small add-on board wired to the circuit inside (illustrative). The two advisories name firmware series rather than individual models."New toy! Asus Wl-520GU" by cibomahto, via flickr, CC-BY-SA-2.0

ASUS published two security records for its routers on Oct. 1, 2026, and the fix for both is a firmware update. The company, which issues CVE identifiers for its own products, scored the more severe of the two, CVE-2026-14157, at 9.4 out of 10 on the CVSS version 4.0 scale and labeled it critical. An assessment attached to both records by the US Cybersecurity and Infrastructure Security Agency lists exploitation as none, its term for no known attacks.

Owners who want to know whether their own router is affected will not find a model list in either record. Both identify the affected software by firmware series: CVE-2026-14157 names the 3.0.0.6_102 series, and CVE-2026-13313, the second record, names the 3.0.0.4_386, 3.0.0.4_388 and 3.0.0.6_102 series. Neither names individual models, and neither gives the version number of the fixed firmware; CVE-2026-13313 points readers to the router firmware section of ASUS's security advisory page instead.

ASUS describes CVE-2026-14157 as a format string flaw, meaning text sent to the device is handled as instructions, and says it lets a remote user who is already logged in run commands of their choosing through a file uploaded in the router's web management interface. It describes the second record as active debug code. A logged-in user can switch on Telnet, an old remote-access service, and run commands with root privileges, which is full control of the device.

Both records list the attacker as an authenticated user, so each assumes someone who can already reach the router's management interface. The two scores differ mainly in difficulty: ASUS rates the format string flaw low in attack complexity and the debug flaw high, which is why they come out at 9.4 and 8.9.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

ASUS Reports Two Router Flaws and Points Owners to a Firmware Update

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.