Skip to content
ASUS Issues Urgent Firmware Updates for Critical Router Vulnerabilities

ASUS Issues Urgent Firmware Updates for Critical Router Vulnerabilities

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •ASUS patched two critical router vulnerabilities with CVSS scores of 9.4 and 8.9.
  • •Users should avoid importing VPN files from untrusted sources to prevent exploitation.
  • •Firmware updates are available for affected router models; immediate installation is recommended.

ASUS has released firmware updates to address two critical vulnerabilities in its routers that could allow authenticated attackers to execute arbitrary commands. The most severe flaw, CVE-2026-14157, has a CVSS score of 9.4 and affects routers running firmware version 3.0.0.6_102. Users are advised to only import VPN configuration files from trusted sources to mitigate risks. A second vulnerability, CVE-2026-13313, rated 8.9, also allows command execution with elevated privileges on several firmware versions. ASUS has not confirmed whether these vulnerabilities have been. Additionally, BIOS updates were issued for 13 motherboard models to fix a separate vulnerability. Users are urged to apply these updates immediately to secure their devices.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
ASUS releases security updates
ASUS issued firmware updates for two critical router vulnerabilities, CVE-2026-14157 and CVE-2026-13313, and BIOS updates for 13 motherboard models.
Cyberinsider
2026-10-01
CVE-2026-14157 published
The critical router vulnerability CVE-2026-14157 was published, allowing command execution via malicious VPN files.
Cyberinsider
2026-10-01
CVE-2026-13313 published
CVE-2026-13313 was published, enabling command execution with elevated privileges on affected routers.
Cyberinsider
2026-10-01
CVE-2026-93495 published
A BIOS vulnerability affecting 13 motherboard models, CVE-2026-93495, was also published.
Cyberinsider

More articles in this cluster (2)

Following this threat?

Track CVE-2026-13313 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the CVE identifiers for the vulnerabilities?
The vulnerabilities are identified as CVE-2026-14157 and CVE-2026-13313 for routers, and CVE-2026-93495 for motherboards.
How can I protect my ASUS router?
Update your router firmware to the latest version and only import VPN files from trusted sources.
Have these vulnerabilities been exploited in the wild?
ASUS has not confirmed any exploitation of these vulnerabilities in real attacks.