TL;DR
ASUS recently disclosed three high-severity hardware and firmware flaws. These ASUS security vulnerabilities impact multiple router models and popular motherboards. Users must apply available firmware updates immediately to secure their devices.
- Product: ASUS (2 products)
- Vulnerabilities: 3 flaws (CVE-2026-13313, CVE-2026-14157, CVE-2026-93495)
- Highest severity: 9.4 (Critical · CVSSv4)
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv4) | Status |
|---|---|---|
| CVE-2026-14157 | 9.4 | Not exploited |
| CVE-2026-13313 | 8.9 | Not exploited |
| CVE-2026-93495 | 7 | Not exploited |
Tired of noisy CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysWhy It Matters
These ASUS security vulnerabilities expose critical network infrastructure to severe risks. Attackers can hijack routing equipment to intercept or control network traffic. Additionally, the motherboard flaws allow physical attackers to extract sensitive memory data. Official sources do not provide exact affected user counts. However, analysts estimate that ASUS hardware serves millions of users globally. Consequently, unpatched systems present highly attractive targets for threat actors.
How The Attack Works
The reported flaws rely on distinct exploitation mechanisms. First, CVE-2026-13313 involves active debug code in router firmware. Authenticated attackers send crafted HTTP requests to bypass standard security checks. This specific action enables the Telnet service for root-level command execution. Second, CVE-2026-14157 stems from an externally controlled format string. Attackers exploit this flaw by uploading crafted files through the web management interface. As a result, they can execute arbitrary commands directly. Finally, CVE-2026-93495 involves improper initialization within specific motherboards. A physically proximate user inserts a malicious USB device to read or write arbitrary memory.
Exploitation Status
Researchers have not published working exploit code. Furthermore, security teams have not confirmed any active exploitation in the wild.
Affected Versions
These flaws impact the 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 router firmware series. Furthermore, multiple motherboards remain vulnerable. These include PRIME Z390-A and ROG MAXIMUS XI models running BIOS versions through 2101.
Patch And Mitigation Steps
Administrators must update affected router firmware immediately. Likewise, you should flash your motherboard BIOS to the newest official release. You must also restrict physical access to critical workstations. This step prevents local hardware attacks entirely. Finally, read the full ASUS security advisory for detailed deployment instructions.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!