Critical Router Flaws

A crafted VPN client configuration file uploaded by a user or logged-in attacker via an Asus router web management interface can allow an adversary to execute arbitrary commands, prompting a critical security patch from the company. A second separate bug utilizing active debug code lets attackers bypass security checks to enable Telnet and potentially run commands with root privileges, affecting devices connected to the router.

Asus recommends that users only import VPN client configuration files from trusted sources. The two vulnerabilities, tracked as CVE-2026-14157 and CVE-2026-13313, received scores of 9.4 and 8.9 out of 10 on the CVSS 4.0 severity scale. Affected firmware includes series 3.0.0.6_102 for both bugs, while the 3.0.0.4_386 and 3.0.0.4_388 series are also impacted by the Telnet flaw.

Routers can act as a VPN client when configured with files from a provider. Issues arise when crafted text inside uploaded files is parsed as formatting instructions rather than plain data. This risk specifically applies to owners importing VPN configuration files directly into the router, rather than running VPN applications on personal devices.

Mitigation and Security Recommendations

The Telnet flaw requires enabling the service prior to executing commands that impact the network. In addition to firmware updates, Asus advises using a strong administrator password containing at least 10 characters with a mix of uppercase letters, numbers, and symbols. Users should also avoid running scripts, tools, or commands from untrusted sources on local network devices to mitigate social engineering risks.

The VPN bug shares an entry point with CVE-2024-0401, a vulnerability disclosed by VulnCheck in 2024 involving crafted OVPN profiles, highlighting the web admin configuration import as a recurring weak point. Past campaigns like AyySSHush have similarly utilized authentication bypasses and command-injection flaws to target routers.

Motherboard Vulnerability

Alongside the router patches, Asus addressed a vulnerability affecting 13 motherboards, where a physically proximate attacker could read or write arbitrary system memory using a specially crafted device. This high-severity flaw, rated 7.0 out of 10, impacts various Z390 and C246 motherboards and requires physical access.

Users can find the relevant firmware updates on the Asus support pages. Motherboard fixes include BIOS version 1502 for the WS Z390 Pro and version 2203 for the remaining 12 affected boards. Routers that have reached end-of-life status will not receive new firmware and should be secured with strong, unique login and Wi-Fi passwords.