Skip to content
Asus Patches Critical Router Vulnerabilities Affecting VPN Configurations

Asus Patches Critical Router Vulnerabilities Affecting VPN Configurations

First seen 4 Oct 2026, 11:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 12:01 UTC
  • •Two critical vulnerabilities in Asus routers allow command execution and root access.
  • •CVE-2026-14157 has a CVSS score of 9.4, while CVE-2026-13313 scores 8.9.
  • •Asus advises immediate firmware updates and caution with VPN configuration files.

Asus has released firmware updates to address two critical vulnerabilities in its routers, CVE-2026-14157 and CVE-2026-13313, both published on October 1, 2026. The first vulnerability allows arbitrary command execution via malicious VPN configuration files, rated critical with a CVSS score of 9.4. The second vulnerability enables Telnet access with root privileges, rated high with a CVSS score of 8.9. Both vulnerabilities affect routers running firmware version 3.0.0.6_102 and are linked to past security issues with Asus's VPN configuration import feature. Users are advised to only use trusted sources for VPN configuration files and to update their firmware immediately. Additionally, Asus has patched a high-severity vulnerability affecting 13 motherboards, allowing physical access to system memory. Users of unsupported routers are recommended to set strong, unique passwords.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-09-11
CVE-2023-39780 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-05-20
CVE-2024-0401 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-01
CVE-2026-14157 and CVE-2026-13313 published
Asus disclosed two critical vulnerabilities affecting router firmware, enabling command execution and Telnet access.
News.Lavx.Hu
2026-10-04
Asus releases firmware updates
Firmware updates were released to address the critical vulnerabilities in affected routers and motherboards.
News.Lavx.Hu

More articles in this cluster (2)

Following this threat?

Track AyySSHush, Asus and CVE-2023-39780 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which router firmware versions are affected?
The vulnerabilities affect routers running firmware version 3.0.0.6_102.
What should users do to protect their devices?
Users should update their router firmware immediately and only use VPN configuration files from trusted sources.
Are there any other vulnerabilities patched in this update?
Yes, Asus also patched a high-severity vulnerability affecting 13 motherboards.