ASUS has released five security advisories addressing seven vulnerabilities affecting router firmware, MyASUS driver components, Aura Wallpaper, and GameSDK. The critical vulnerability, CVE-2026-13385 (CVSS 9.5), allows machine-in-the-middle attackers to execute arbitrary commands on CN SKU routers without credentials.
Other identified vulnerabilities include driver flaws enabling local administrative access to physical memory and insufficient input validation in web interfaces, all of which pose significant security risks. ASUS advises users to apply the latest security updates immediately, with no active exploitation of the flaws confirmed at this time.