HomeSecurityCritical vulnerability in ASUS Router allows command execution

Critical vulnerability in ASUS Router allows command execution

ASUS is warning about CVE-2026-14157, a critical vulnerability that could allow arbitrary command execution on the company's routers. The vulnerability affects the ASUS Router with firmware 3.0.0.6_102 and requires an elevated account. ASUS' official security advisory recommends immediate patching.

VPN settings file on ASUS Router

The issue concerns the process of importing a configuration file for a VPN client through the web management interface. A specially crafted file could lead to the execution of commands on the router, posing a risk to the integrity, confidentiality, and availability of the device.

How the ASUS Router Vulnerability Works

According to ASUS, the vulnerability is located in the router's management interface and is triggered when a user imports a maliciously crafted VPN configuration file. The bulletin describes the possibility of executing arbitrary commands, without publishing technical details about the bug or ready-made exploit code.

The at 9.4/10 on the latest CVSS 4.0 scale. However, the assessment vector records high privilege requirements, so this is not an anonymous, unlogged attack. This does not negate the risk, especially in networks where multiple users may manage or configure devices.

For IT teams, this requirement also focuses on protecting administrative accounts. Avoiding shared passwords, removing unused accounts, and limiting who can import configuration files reduce the potential for abuse by an already authorized account.

ASUS does not specify in the announcement whether the vulnerability has been exploited in real attacks, nor does it name specific models or versions that fix the issue. Therefore, administrators should not assume that a model is exempt because it is not specifically named; they should check the software version from the official support page.

See also: D-Link DIR-822A: Critical vulnerabilities threaten routers

Risk to the corporate network via router

Which ASUS routers are affected?

ASUS lists the affected software series as 3.0.0.6_102. The bulletin does not include a detailed list of models or patch numbers. The vulnerability's listing on the National Vulnerability Database confirms the specific series, but also does not list models or a final patch version.

The manufacturer's recommendation is to install the latest available software for each model. The update should be sought from official ASUS support or the corresponding product page, as version numbers vary per device. There is no specific single version number that fixes all models.

The distinction has practical significance: a general indication of "updated" is not enough if the router is still using older software. Administrators must check the device environment for the exact version number and compare it with the one available for the specific model from ASUS.

In enterprise networks, testing can be done on all registered models, not just one pilot tested device. Recording the model and current version helps identify routers that are out of date or no longer supported by the manufacturer.

See also: Tenda CP3: Critical vulnerability allows remote command execution

ASUS router software update

How is the risk limited?

Until the update is complete, ASUS requests that VPN configuration files be imported only from sources that are known and trusted. Files that are publicly available, come from unknown senders, or cannot be verified should be avoided. The warning specifically applies to the file import function in the management interface.

The SecNews technical team also recommends limiting access to ASUS Router management to those who need it, ideally only from the local network or via a secure access channel. Administrator passwords should be strong and unique, while remote management should be disabled when not needed.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

After installing the update, organizations can verify that the version is correctly displayed on the device and check that VPN file import operations are restricted to authorized administrators. ASUS does not describe a separate workaround in the announcement that replaces the update.

CVE-2026-14157 does not require anonymous access, but the high score and the ability to execute commands make the update a priority for devices in the 3.0.0.6_102 series. Those with an ASUS Router should immediately check their model, install the latest available version, and discard unverified VPN configuration files.

See also: Governments to businesses: Improve the security of your routers

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS