- Asus issued security patches for two severe vulnerabilities affecting several of its router firmware lines.
- The highest-rated flaw (CVE-2026-14157, CVSS 9.4) allows arbitrary command execution via malicious VPN configuration files.
- A second bug (CVE-2026-13313, CVSS 8.9) allows attackers to bypass checks and enable Telnet with root access using leftover debug code.
Tech giant Asus has rolled out critical security patches to address two severe vulnerabilities affecting its router lineup. If left unpatched, these bugs could allow attackers to execute arbitrary commands on the devices or gain root-level Telnet access, potentially compromising the entire local network.
The most critical of the two flaws, tracked as CVE-2026-14157, carries a near-maximum severity rating of 9.4 on the CVSS 4.0 scale. The vulnerability is triggered when a user or a logged-in attacker uploads a maliciously crafted VPN client configuration file via the router’s web management interface. Instead of reading the file’s contents purely as data, the system parses specific crafted text as formatting instructions, triggering command execution.
Inside the Security Patches and Telnet Flaws
The second security flaw, tracked as CVE-2026-13313, scores an 8.9 on the CVSS scale. This vulnerability stems from active debug code left in the production firmware. An attacker logged into the web interface can exploit this leftover code to bypass standard security checks, enable the router’s Telnet service, and run commands with root privileges.
These vulnerabilities primarily target users who configure their routers to act as VPN clients directly, rather than running VPN applications on individual laptops or smartphones. Asus has confirmed that both bugs affect the 3.0.0.6_102 firmware series, while the Telnet bug also impacts the older 3.0.0.4_386 and 3.0.0.4_388 firmware series. Users are strongly urged to update their router firmware immediately and only import VPN configuration files from trusted sources.
Source: Original Coverage


Leave a Reply