TL;DR
ASUS has published five security advisories covering seven vulnerabilities. They span router firmware, MyASUS driver components, Aura Wallpaper, and GameSDK. The most severe, CVE-2026-13385 (CVSS 9.5), lets a machine-in-the-middle attacker push arbitrary commands to CN SKU routers. ASUS reports no in-the-wild exploitation, and no public proof-of-concept exists.
Why It Matters
ASUS routers and laptops sit in homes and offices worldwide. Router flaws matter most, since these devices guard the network edge. The critical bug needs no credentials at all. Meanwhile, the driver flaws let a local administrator read and write physical memory, which breaks OS-enforced protections. Attackers use that kind of access to disable security tools.
How the Attacks Work
CVE-2026-13385: Certificate Validation Failure (CVSS 9.5)
The UU feature in CN SKU ASUSWRT firmware validates certificates improperly. Consequently, a network-positioned attacker can spoof the update server. The router then downloads and runs attacker-supplied commands.
Driver Flaws in MyASUS Components
CVE-2026-15029 (CVSS 8.4) is an untrusted pointer dereference in ASUS System Control Interface v3 and ASUS Business Manager. Crafted IOCTL requests give a local administrator arbitrary physical memory read and write. Separately, CVE-2026-13585 (CVSS 8.2) mixes missing resource throttling with data left behind before reuse. That combination discloses sensitive information and may trigger a denial of service. A third flaw, CVE-2026-15030 (CVSS 5.6), affects the same driver family.
Router Web Interface and Utilities
CVE-2026-11851 (CVSS 5.9) allows a remote authenticated user to disclose information through a crafted request that slips past input validation. On the software side, CVE-2026-8920 (CVSS 8.5) lets a local user perform unauthorized file operations via Aura Wallpaper Service. Finally, CVE-2026-8919 (CVSS 7.2) exposes local credentials and enables data tampering through ASUS GameSDK.
- Total: 7 CVEs
- Severity: 1 Critical · 4 High · 2 Medium
- Actively exploited: None confirmed
- Highest severity: 9.5 (Critical · CVSSv4) — CVE-2026-13385
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-13385 | 9.5 | — | — | Not exploited |
| CVE-2026-8920 | 8.5 | — | — | Not exploited |
| CVE-2026-15029 | 8.4 | — | v3.1.65.0, v1.1.40.0 | Not exploited |
| CVE-2026-13585 | 8.2 | — | v3.1.66.0, v1.1.40.0 | Not exploited |
| CVE-2026-8919 | 7.2 | — | — | Not exploited |
| CVE-2026-11851 | 5.9 | — | — | Not exploited |
| CVE-2026-15030 | 5.6 | — | v3.1.65.0, v1.1.40.0 | Not exploited |
Affected Versions
CVE-2026-13385 affects only CN SKU models running the UU feature on ASUSWRT 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. Other regions escape this one. The driver flaws reach all ASUS personal computers, including desktops, laptops, NUCs, and All-in-One PCs. ASUS fixed Aura Wallpaper in v2.2.2.0 and GameSDK in v1.0.6.0.
Patch and Mitigation Steps
Update router firmware from the ASUS Support or Networking product pages first. For PCs, pull the System Control Interface update through MyASUS, the support site, or Windows Update. Armoury Crate handles the Aura Wallpaper and GameSDK updates under Update Center.
If you cannot patch a router immediately, ASUS suggests turning off Traffic Analyzer and Adaptive QoS. Additionally, keep the web interface on trusted local networks and disable WAN-facing services such as remote access, DDNS, VPN server, DMZ, and FTP. Sign out of management sessions and back in after updating. Owners of EOL models unsupported after March 2026 should replace the device, or at minimum disable the UU feature. Each write-up appears on the ASUS security advisory page.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.