← Back to CVE List
CVE-2026-13313NVD
Vulnerability Summary
An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router.
Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
CVSS v4.0 Base Metrics — Score 8.9 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Attack RequirementsNone
Privileges RequiredHigh
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)High
Integrity (Subsequent System)High
Availability (Subsequent System)High
Affected & Patched Versions
- ASUS Router >= 3.0.0.4_386 series
- ASUS Router >= 3.0.0.4_388 series
- ASUS Router >= 3.0.0.6_102 series
Not provided by cveorg for this CVE.