Asus has patched two router vulnerabilities that can be exploited through the web management interface. The more severe, CVE-2026-14157, scores 9.4 on the CVSS 4.0 scale and involves a crafted VPN client configuration file that lets an attacker execute arbitrary commands. The second, CVE-2026-13313, scores 8.9 and stems from debug code left active, allowing a logged-in attacker to bypass security checks, enable Telnet, and potentially run commands with root privileges.
The VPN issue arises when users import a VPN client configuration file into the router itself; crafted text in the file is interpreted as formatting instructions rather than plain data. Asus names firmware series rather than specific models: 3.0.0.6_102 is affected by both bugs, while 3.0.0.4_386 and 3.0.0.4_388 are also affected by the Telnet flaw. The company advises importing VPN configs only from trusted sources and using a strong, unique admin password of at least 10 characters with uppercase letters, numbers, and symbols.
The same VPN config entry point was used in a 2024 vulnerability (CVE-2024-0401), and Asus routers have been a target of campaigns such as AyySSHush, which backdoored over 9,000 routers. Alongside the router fixes, Asus released BIOS updates for 13 motherboards, including the WS Z390 Pro (version 1502) and 12 other boards (version 2203), to address a high-severity flaw that allows a physically proximate attacker to read or write arbitrary system memory. Routers that have reached end of life will not receive new firmware, so Asus recommends strong, unique login and Wi-Fi passwords for those devices.