securityonline.info 7 Oct 2026, 03:05 UTC

ASUS Patches Critical Router Flaws That Could Expose Settings

ASUS Patches Critical Router Flaws That Could Expose Settings
CyberSIXT Evidence Panel

ASUS has issued a firmware update for its routers addressing four security flaws, two of which are rated Critical with CVSSv4 scores of 9.3. The four CVEs affected are CVE-2026-14911, CVE-2026-19386, CVE-2026-16528 and CVE-2026-19396. The vendor notes that there is no confirmed exploitation in the wild at the time of the advisory, but urges users to update to the latest firmware immediately to mitigate potential risks.

The issues span three affected firmware lines: 3.0.0[.]6.102 (all four flaws) and the 3.0.0[.]4.386 and 3.0.0[.]4.388 series (the latter only for CVE-2026-16528).

CVE-2026-14911 describes a cross-site scripting flaw in ASUS router modules that can allow an authenticated attacker to read page data, alter settings, or cause a denial of service when a crafted URL is accessed. CVE-2026-19386 is a stack-based buffer overflow that enables an authenticated nearby user to execute arbitrary code via a crafted configuration file upload. CVE-2026-16528 concerns leaking DDNS credentials into system logs, enabling an authenticated attacker who reads the logs to change DNS settings.

CVE-2026-19396 relates to a predictable IFTTT token seed used during pairing, allowing a nearby attacker to derive tokens and read or modify router settings. ASUS’ patch process involves installing the newest firmware and rebooting to clear tokens; interim mitigations include disabling WAN remote access and avoiding untrusted links to the router admin page, plus avoiding untrusted configuration restores.

View full article

Article by CyberSIXT