
ASUS has released router firmware updates to address two vulnerabilities that could allow authenticated remote attackers to execute commands on affected devices, including a critical flaw involving malicious VPN configuration files.
The company also issued BIOS updates for 13 motherboard models to fix a separate vulnerability that could let an attacker with physical access read or modify system memory. All three security bulletins were last updated on October 1, 2026.
ASUS, the Taiwanese manufacturer of computers, networking equipment, and PC components, is urging users to install the latest firmware immediately.
Bad VPN files to code execution on the router
The most severe issue, tracked as CVE-2026-14157, carries a CVSS v4.0 score of 9.4 and affects the router’s web management interface on the 3.0.0.6_102 series firmware. An authenticated attacker could exploit it by uploading a specially crafted VPN client configuration file, causing the device to execute arbitrary commands.
Until they apply the update, users should import VPN client configuration files only from trusted sources. ASUS warns against using publicly shared files, files obtained from unknown sources, or configurations whose trustworthiness cannot be verified.
The second router vulnerability, CVE-2026-13313, is rated high severity with a CVSS v4.0 score of 8.9. ASUS says it allows an authenticated remote attacker to execute commands with elevated privileges.
The flaw impacts 3.0.0.4_386 series, 3.0.0.4_388 series, and 3.0.0.6_102 series router firmware versions.
ASUS recommends strong, unique router administration passwords containing at least 10 characters, with uppercase letters, numbers, and symbols.
It also warns users against running untrusted scripts, tools, or commands on devices within their local network. Attackers could use social engineering to persuade administrators to execute crafted commands that interact with the router’s management interface.
Neither router bulletin states whether the vulnerabilities have been exploited in attacks.
BIOS updates for 13 motherboards
The motherboard vulnerability, CVE-2026-93495, has a CVSS v4.0 score of 7.0 and stems from improper initialization. Exploitation involves inserting a specially crafted device, which could allow arbitrary reads or writes to system memory.
The affected models and required BIOS updates are:
- PRIME Z390-A, Z390-A/H10, fixed in version 2203
- ROG MAXIMUS XI HERO, HERO (WI-FI), FORMULA, CODE, EXTREME, APEX, GENE, fixed in version 2203
- ROG STRIX Z390-E GAMING, Z390-F GAMING, fixed in version 2203
- Pro WS C246-ACE, fixed in version 2203
- WS Z390 PRO, fixed in version 1502
Users should download firmware and BIOS updates for their exact model from ASUS Support.
For routers that no longer receive firmware updates, ASUS recommends strong, unique administration and Wi-Fi passwords and directs owners to its end-of-life product list. These precautions reduce exposure but do not patch the vulnerabilities.







Leave a Reply