Asus Patches Critical VPN Config Flaw Enabling Router Command Execution
Asus patched a CVSS 9.4 router flaw letting crafted VPN config files execute arbitrary commands, plus a Telnet bug enabling root access and a 13-board motherboard memory flaw.
- By
- Sophie Lindqvist
- Filed
- Channel
- Hardware & Components
- Read
- 3 min read
Asus has patched a critical router vulnerability scored 9.4 out of 10 on CVSS 4.0, which lets a crafted VPN client configuration file execute arbitrary commands on affected routers. A second flaw, scored 8.9, allows a logged-in attacker to enable Telnet and potentially run commands with root privileges.
The first bug, tracked as CVE-2026-14157, triggers when a router parses an uploaded VPN client configuration file as formatting instructions rather than plain data. A user — or an attacker who has already logged in — uploads the malicious file through the router's web management interface. The router then interprets the crafted text as commands it executes. Asus's routers can act as VPN clients when configured with a file from a VPN provider, and the risk applies to configurations imported into the router itself, not to VPN apps running on a laptop or phone.
The second vulnerability, CVE-2026-13313, exploits debug code left active in the firmware. It lets an attacker bypass security checks to enable Telnet, from which commands could be run with root privileges, potentially affecting devices connected to the router. The attacker must first enable the service before running commands that could impact the network.
Asus identifies affected devices by firmware series rather than model. Both bugs affect firmware series 3.0.0.6_102, while the 3.0.0.4_386 and 3.0.0.4_388 series are also exposed to the Telnet flaw. Fixes are available on Asus's support pages and individual product pages.
The VPN bug reuses the same entry point as CVE-2024-0401, disclosed by VulnCheck in 2024, which also relied on a crafted OVPN profile. The web admin configuration import has now proven a recurring weak point in Asus's router stack. The brand's popularity also makes it a frequent target: the AyySSHush campaign combined authentication bypasses, brute-force logins, and the command-injection flaw CVE-2023-39780 to backdoor more than 9,000 Asus routers, with a backdoor that survived firmware updates.
Beyond the two router patches, Asus fixed a flaw affecting 13 motherboards, mostly in its Z390 and C246 lines, rated 7.0 on CVSS. A "physically proximate attacker" could "read or write arbitrary system memory by inserting a specially crafted device," according to the company. The lower score reflects the physical access requirement. The fix ships as BIOS version 1502 for the WS Z390 Pro and version 2203 for the other 12 boards.
Asus advises users to "only import VPN client configuration files from trusted sources." For interim protection, it recommends a strong, unique admin password with "at least 10 characters, with a mix of uppercase letters, numbers, and symbols," and warns against running "scripts, tools, or commands from untrusted sources on any device within your local network." The company also flags that "attackers may use social engineering to trick administrators."
Routers that have reached end of life will not receive new firmware. For those devices, Asus advises strong, unique login and Wi-Fi passwords as the only mitigation. Owners of supported routers and the 13 motherboards can find the updates on Asus's support site now, and the repeat appearance of the configuration-import attack path suggests future patches will continue to focus on that interface.
Source: Tom's Hardware
More from Sophie Lindqvist
Related articles
asus-wins-fcc-exemption-from-us-foreign-router-ban-without-a-public-us-fab-plan-26c43867
Asus Wins FCC Exemption From US Foreign-Router Ban — Without a Public US Fab Plan
relapse-exploit-brings-ps5-jailbreaking-to-current-firmware-43942083
Relapse Exploit Brings PS5 Jailbreaking to Current Firmware
bad-data-not-bad-actors-drives-chip-export-compliance-risk-6a09d946
Bad Data, Not Bad Actors, Drives Chip Export Compliance Risk
fasoo-ai-aims-to-double-semiconductor-security-sales-3c15ff9b
Fasoo AI Aims to Double Semiconductor Security Sales



