important · Wi-Fi / edge
Two authenticated ASUS router-management paths permit operating-system command execution.
Affects
ASUS consumer routers running the vendor's embedded router firmware.
One path consumes uploaded management data as a format string; the other reaches active debug code that enables root Telnet access.
Detail and 5 sources
Because both paths require high-privilege router administration, the new capability is operating-system execution rather than new administrative access.
ASUS released firmware updates for the affected router series.
Sources
ResearchCVE-2026-14157 - Vulnerability Details - OpenCVEResearchCVE-2026-13313 - Vulnerability Details - OpenCVEResearchVulnerabilità in prodotti ASUS (AL02/261001/CSIRT-ITA) – CSIRT ToscanaVendorASUS Security Advisory | Latest Vulnerability UpdateVendorMalicious VPN config files can let attackers run commands on Asus routers — company’s patch also fixes a bug that lets a logged-in attacker switch on Telnet with root access | Tom's Hardware