Asus patches critical router flaws: malicious VPN configs and Telnet backdoor
Asus released firmware updates fixing two router vulnerabilities: one allowing arbitrary command execution via crafted VPN configuration files (CVE-2026-14157) and another enabling Telnet access with root privileges (CVE-2026-13313).
Asus has released firmware updates to address two security vulnerabilities in its routers, one of which is rated critical. The flaws allow attackers to execute arbitrary commands or gain root-level access to the device.
The more severe issue, tracked as CVE-2026-14157 with a CVSS score of 9.4 out of 10, stems from how the router's web management interface processes VPN client configuration files. A crafted file uploaded by a user or a logged-in attacker can be interpreted as formatting instructions rather than plain data, enabling the execution of arbitrary commands on the device.
Asus recommends that users only import VPN client configuration files from trusted sources. The vulnerability affects routers running firmware version 3.0.0.6_102, which is the same series impacted by the second flaw.
The second bug, CVE-2026-13313, scores 8.9 on the CVSS scale. It involves debug code left active in the firmware that allows an attacker to bypass security checks and enable Telnet. Once Telnet is active, the attacker may be able to run commands with root privileges, potentially affecting other devices connected to the network. This issue also affects the 3.0.0.4_386 and 3.0.0.4_388 firmware series.
The VPN configuration vulnerability uses the same entry point as a flaw disclosed by VulnCheck in 2024, CVE-2024-0401, which exploited a crafted OVPN profile. This makes Asus's config file import feature a recurring weak point, and the company's popularity makes it a likely target for attackers.
Asus's routers have been targeted before. The AyySSHush campaign used authentication bypasses, brute-force logins, and a command-injection flaw (CVE-2023-39780) to backdoor over 9,000 routers, with the backdoor surviving firmware updates.
Alongside the router fixes, Asus also patched a vulnerability affecting 13 motherboards. A physically proximate attacker could read or write arbitrary system memory by inserting a specially crafted device. This flaw impacts many of Asus's Z390 and C246 motherboards and is rated high severity at 7.0 out of 10.
Asus advises users to update their router firmware via the company's support page or their product's page. For affected motherboards, the fix is BIOS version 1502 for the WS Z390 Pro and 2203 for the other 12 boards. Routers that have reached end of life will not receive new firmware, and Asus recommends users of those devices set strong, unique login and Wi-Fi passwords.
In the meantime, Asus suggests using a strong, unique admin password with at least 10 characters, including uppercase letters, numbers, and symbols. The company also advises against running scripts, tools, or commands from untrusted sources on any device within the local network, noting that attackers may use social engineering to trick administrators.
Source : tomshardware.com
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
