Vietnam.Vn Asus Patches Critical Router Vulnerabilities Affecting VPN Configurations
Article Content
- •Two critical vulnerabilities in Asus routers allow command execution and root access.
- •CVE-2026-14157 has a CVSS score of 9.4, while CVE-2026-13313 scores 8.9.
- •Asus advises immediate firmware updates and caution with VPN configuration files.
Asus has released firmware updates to address two critical vulnerabilities in its routers, CVE-2026-14157 and CVE-2026-13313, both published on October 1, 2026. The first vulnerability allows arbitrary command execution via malicious VPN configuration files, rated critical with a CVSS score of 9.4. The second vulnerability enables Telnet access with root privileges, rated high with a CVSS score of 8.9. Both vulnerabilities affect routers running firmware version 3.0.0.6_102 and are linked to past security issues with Asus's VPN configuration import feature. Users are advised to only use trusted sources for VPN configuration files and to update their firmware immediately. Additionally, Asus has patched a high-severity vulnerability affecting 13 motherboards, allowing physical access to system memory. Users of unsupported routers are recommended to set strong, unique passwords.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AyySSHush, Asus and CVE-2023-39780 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which router firmware versions are affected?
What should users do to protect their devices?
Are there any other vulnerabilities patched in this update?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…