ASUS Reports Two Router Flaws and Points Owners to a Firmware Update

ASUS published two security records for its routers on Oct. 1, 2026, and the fix for both is a firmware update. The company, which issues CVE identifiers for its own products, scored the more severe of the two, CVE-2026-14157, at 9.4 out of 10 on the CVSS version 4.0 scale and labeled it critical. An assessment attached to both records by the US Cybersecurity and Infrastructure Security Agency lists exploitation as none, its term for no known attacks.
Owners who want to know whether their own router is affected will not find a model list in either record. Both identify the affected software by firmware series: CVE-2026-14157 names the 3.0.0.6_102 series, and CVE-2026-13313, the second record, names the 3.0.0.4_386, 3.0.0.4_388 and 3.0.0.6_102 series. Neither names individual models, and neither gives the version number of the fixed firmware; CVE-2026-13313 points readers to the router firmware section of ASUS's security advisory page instead.
ASUS describes CVE-2026-14157 as a format string flaw, meaning text sent to the device is handled as instructions, and says it lets a remote user who is already logged in run commands of their choosing through a file uploaded in the router's web management interface. It describes the second record as active debug code. A logged-in user can switch on Telnet, an old remote-access service, and run commands with root privileges, which is full control of the device.
Both records list the attacker as an authenticated user, so each assumes someone who can already reach the router's management interface. The two scores differ mainly in difficulty: ASUS rates the format string flaw low in attack complexity and the debug flaw high, which is why they come out at 9.4 and 8.9.
