Asus Router Security Flaws Allow Remote Commands via VPN Files
Asus has addressed critical security vulnerabilities impacting its routers and motherboards, releasing firmware updates to protect users from potential remote command execution and system memory risks.

Critical Vulnerabilities in Asus Routers
Asus has [acted to patch] a critical security flaw affecting its routers that could allow malicious actors to run commands on targeted devices. According to reports, a crafted VPN client configuration file uploaded via a router's web management interface permits an adversary to execute arbitrary commands. The primary flaw is tracked as CVE-2026-14157.
A second, separate bug designated as CVE-2026-13313 relies on left-active debug code. This flaw enables attackers to bypass security checks in order to switch on Telnet, potentially allowing commands to be run with root privileges. Asus rates the VPN file flaw as critical, assigning it a score of 9.4 out of 10 on the CVSS 4.0 scale, while the Telnet flaw scores 8.9 out of 10.
Affected Firmware Series and Recommendations
Asus has identified affected devices by firmware series rather than specific individual model numbers. The 3.0.0.6_102 firmware series is impacted by both the VPN file vulnerability and the Telnet bug, while the older 3.0.0.4_386 and 3.0.0.4_388 series are also affected by the Telnet security issue.
Until routers running the 3.0.0.6_102 firmware are successfully updated, Asus explicitly advises users not to import untrusted VPN files. The company recommends that users only import VPN client configuration files originating from trusted sources.
To further mitigate potential risks, Asus encourages administrators to employ strong and unique admin passwords containing at least 10 characters, including a mix of uppercase letters, numbers, and symbols. Users should also avoid running scripts, tools, or commands from untrusted sources on any connected device within their local network.
Context of Recurring Import Flaws
The VPN configuration file vulnerability shares a similar entry point with a previous security issue disclosed by VulnCheck in 2024, known as CVE-2024-0401, which similarly exploited a crafted OpenVPN profile. This history highlights the web admin configuration file import feature as a recurring weak point for the brand.
As a prominent and widely used network equipment brand, Asus routers remain frequent targets for cyber threats. Past campaigns, such as the AyySSHush botnet activity, have targeted Asus routers using authentication bypasses and command-injection flaws to establish persistent backdoors across thousands of devices.
Additional Motherboard Security Patch
Alongside the router security fixes, Asus also rolled out a security patch addressing a vulnerability across 13 motherboard models. This flaw allows a physically proximate attacker to read or write arbitrary system memory by inserting a specially crafted device.
Impacted hardware includes multiple models from Asus's Z390 and C246 motherboard lineups. Rated as high severity with a CVSS score of 7.0 out of 10, this specific issue requires direct physical access to the machine to exploit.
Affected motherboard users can secure their systems by updating to BIOS version 1502 for the WS Z390 Pro and version 2203 for the remaining 12 compatible boards.
End-of-Life Devices and Where to Find Updates
Users seeking to secure potentially vulnerable hardware can find the appropriate firmware updates directly on the official Asus support page or via their specific product page. However, routers that have reached their end-of-life status will not receive new firmware patches.
For owners of legacy or end-of-life hardware that will no longer receive vendor updates, Asus strongly advises maintaining robust operational security by configuring strong, unique login credentials and Wi-Fi passwords to deter unauthorized access.
Sources
- Tom's HardwareMalicious VPN config files can let attackers run commands on Asus routers
Continue chronologically




