Vulnerability
Published 2026-10-01
Verified 2026-10-03

ASUS routers CVE-2026-14157 (CVSS 4.0 9.4): crafted VPN client config → arbitrary commands; CVE-2026-13313 8.9 Telnet/root — update firmware

ASUS product security notices (last updated 1 October 2026; amplified by CyberInsider 1 Oct and Tom's Hardware 3 Oct) address two authenticated remote flaws in consumer/prosumer router firmware reachable via the web management interface. CVE-2026-14157 (Critical, CVSS v4.0 9.4): a specially crafted VPN client configuration file uploaded through the management UI can cause arbitrary command execution on firmware series 3.0.0.6_102. Until patched, ASUS says import VPN client configs only from trusted, verifiable sources — avoid publicly shared or unknown-origin OVPN/profile files. CVE-2026-13313 (High, CVSS v4.0 8.9): authenticated attacker can bypass checks (debug code left active) to enable Telnet and run commands with elevated/root privileges; affects 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. ASUS also recommends a strong unique admin password (≥10 chars, upper/number/symbol mix) and against running untrusted scripts/tools/commands on LAN hosts that can reach the router UI. Neither router bulletin states exploitation in the wild. Separate same-day board notice: CVE-2026-93495 (CVSS v4.0 7.0) improper BIOS init — physical crafted device → memory R/W on listed Z390/C246 boards (BIOS 2203 / 1502). Primary wire: CyberInsider 1 Oct (cites ASUS bulletins); vendor landing: ASUS Product Security Advisory; models: install latest firmware for exact SKU from ASUS Support. ASUS security-advisory HTML table was empty on fetch (likely JS) — switch primary_url when the specific bulletin permalink is listed.

Product
ASUS routers (web management VPN client import / Telnet debug path); optional: listed Z390/C246 motherboards (BIOS CVE-2026-93495)
Versions
Routers: CVE-2026-14157 on 3.0.0.6_102 series; CVE-2026-13313 on 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. Fixed: latest firmware per model from ASUS Support (series named; exact build strings not in wire copy). BIOS CVE-2026-93495: listed PRIME/ROG/Pro WS Z390 and C246 models — BIOS 2203 or 1502 as applicable.
CVSS
9.4
Exploited in Australia?
unknown
Patch to
Install the latest ASUS router firmware for your exact model from ASUS Support. Until then: import VPN client configuration files only from trusted sources; set a strong unique admin password; do not run untrusted scripts/tools against the LAN management UI. EOL routers: harden passwords and review ASUS end-of-life guidance (does not replace a patch). Motherboard owners: apply listed BIOS updates for CVE-2026-93495.

Primary: CyberInsider — ASUS warns of critical router flaw via malicious VPN files (1 Oct 2026) · Vendor: ASUS Product Security Advisory (watch for CVE-2026-14157 / 13313 bulletin rows) · CVE: CVE-2026-14157, CVE-2026-13313, CVE-2026-93495 · Tom's Hardware — malicious VPN config command execution on ASUS routers (3 Oct 2026)

vulnerabilities network