TL;DR
ASUS has released router firmware that fixes four security flaws, and two of them rate Critical with a CVSS 4.0 score of 9.3. These ASUS router vulnerabilities can lead to settings changes, credential theft or code execution. ASUS urges all users to install the latest firmware now.
- Product: ASUS Router
- Vulnerabilities: 4 flaws (CVE-2026-14911, CVE-2026-19386, CVE-2026-16528, CVE-2026-19396)
- Highest severity: 9.3 (Critical · CVSSv4)
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv4) | Status |
|---|---|---|
| CVE-2026-14911 | 9.3 | Not exploited |
| CVE-2026-19386 | 9.3 | Not exploited |
| CVE-2026-16528 | 8.4 | Not exploited |
| CVE-2026-19396 | 7.7 | Not exploited |
Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.
Try Team free for 14 daysWhy It Matters
Home and small-office routers sit between every device and the internet. An attacker who controls one can watch traffic or redirect users to fake sites. ASUS routers are a common choice for both homes and small businesses.
The vendor’s message is direct. “ASUS strongly recommends that all users update their router firmware to the latest version immediately,” the advisory says. Even so, ASUS does not report any exploitation in the wild or a public proof-of-concept.
How the Attacks Work
Cross-Site Scripting (CVE-2026-14911)
This critical bug is a cross-site scripting flaw in router modules. It triggers “when an authenticated user visits a crafted URL.” From there, an attacker can read page data, change router settings and cause a denial of service.
Code Execution via Config Upload (CVE-2026-19386)
The second critical flaw is a stack-based buffer overflow. Per the CVE record, it “allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload.” The attacker needs admin rights and a nearby network position.
Leaked DDNS Credentials (CVE-2026-16528)
This high-severity bug, rated 8.4, writes DDNS credentials into the system log. An authenticated attacker who reads that log could then change DNS settings.
Predictable IFTTT Token (CVE-2026-19396)
The last flaw, rated 7.7, affects the RT-BE57. It uses a predictable seed to create IFTTT pairing tokens. As a result, a nearby attacker who watches a pairing session could derive the token and read or modify router settings.
Affected Versions
The ASUS router vulnerabilities hit these firmware lines:
- 3.0.0.6.102 series: all four flaws
- 3.0.0.4.386 and 3.0.0.4.388 series: CVE-2026-16528 only
ASUS does not list exact fixed build numbers. Instead, it points users to the newest firmware for each model.
Patch and Mitigation Steps
Download the latest firmware from the ASUS Support page or your router’s product page. Afterwards, reboot the router to clear any old pairing tokens.
Until you update, ASUS suggests several steps:
- Avoid untrusted links that point to the router admin page.
- Disable remote access from the WAN side.
- Skip IFTTT pairing while untrusted devices share your network.
- Do not restore configuration backups from untrusted sources.
For end-of-life models, ASUS advises following these steps and “consider replacing the device with a currently supported model.” Together, these measures limit exposure to the ASUS router vulnerabilities until the patch is in place.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!