securityonline.info 1 Oct 2026, 03:39 UTC

ASUS Routers and Motherboards Exposed to High-Risk Flaws

ASUS Routers and Motherboards Exposed to High-Risk Flaws
CyberSIXT Evidence Panel

ASUS has disclosed three high-severity hardware and firmware flaws affecting a range of router models and popular motherboards. The vulnerabilities, tracked as CVE-2026-14157, CVE-2026-13313 and CVE-2026-93495, carry CVSSv4 scores up to 9.4 and have not been observed exploited in the wild to date. The affected router firmware versions are 3.0.0.4_386, 3.0.0.4_388 and 3.0.0.6_102, while affected motherboards include PRIME Z390‑A and ROG MAXIMUS XI running BIOS versions up to 2101. Official ASUS advisories remain the primary source for deployment details.

CVE-2026-13313 involves active debug code within router firmware that can be triggered by authenticated attackers sending crafted HTTP requests to bypass standard security checks, enabling Telnet at root level. CVE-2026-14157 stems from an externally controlled format string vulnerability that allows attackers to upload crafted files via the web management interface, potentially enabling arbitrary command execution.

CVE-2026-93495 concerns improper initialization on certain motherboards; a physically proximate user could insert a malicious USB device to read or write arbitrary memory. At present, there is no published exploit code nor confirmed in‑the‑wild exploitation. Administrators are urged to apply available firmware updates promptly and to flash the corresponding motherboard BIOS to the latest official release, while also restricting physical access to critical devices. For deployment instructions and detailed mitigations, refer to the ASUS security advisory.

View full article

Article by CyberSIXT