← Back to CVE List
CVE-2026-13385NVD
Vulnerability Summary
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server.
Refer to the '
Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Refer to the '
Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
CVSS v4.0 Base Metrics — Score 9.5 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)High
Integrity (Subsequent System)High
Availability (Subsequent System)High
Affected & Patched Versions
- ASUS Router >= 3.0.0.4_386 series
- ASUS Router >= 3.0.0.4_388 series
- ASUS Router >= 3.0.0.6_102 series
Not provided by cveorg for this CVE.