ASUS has released an urgent security update for its routers after discovering a critical vulnerability that allows an authenticated attacker to execute commands on the device through a specially crafted VPN file. The flaw received a severity score of 9.4 out of 10 and affects routers running firmware from the 3.0.0.6_102 series.
The vulnerability is tracked as CVE-2026-14157 and affects the router’s web-based administration interface. To exploit it, an attacker must already have access to the management panel, after which they can upload a specially crafted VPN client configuration file and use it to execute commands on the device. The greatest risk applies to users who import VPN configurations from the internet or obtain them from untrusted sources. In its official security advisory, ASUS recommends avoiding VPN files whose origin cannot be verified and installing the latest firmware version available for the specific router model.
Alongside CVE-2026-14157, the company patched another serious flaw, CVE-2026-13313, which received a severity score of 8.9 out of 10 and affects firmware versions in the 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. In this case, an authenticated remote attacker can also execute commands, but with elevated privileges. ASUS recommends using a strong and unique router administrator password and avoiding untrusted scripts, tools, or commands on devices connected to the home network.
The company also warns that attackers may use social engineering to trick administrators into manually executing specially crafted commands that interact with the router’s management interface.
“Attackers may use social engineering to trick administrators into executing specially crafted commands that interact with the router’s administration interface,” ASUS warned in its October 1 advisory.
ASUS has not said whether CVE-2026-14157 or CVE-2026-13313 have been exploited in real-world attacks. The company also fixed a third vulnerability, CVE-2026-93495, which affects 13 ASUS motherboard models and received a severity score of 7.0. Exploiting this flaw requires physical access to the device and specially prepared hardware, so owners of affected motherboards are advised to install the latest BIOS version available for their model.
Routers have long attracted attackers because they sit between users and the internet and can serve as convenient intermediary nodes for hiding malicious activity. Last year, researchers uncovered a Chinese cyberespionage campaign in which more than 50,000 home ASUS routers were hijacked. The attackers exploited known vulnerabilities in older and unsupported models that no longer received security updates.
The compromised devices were grouped into a covert network through which attackers could route traffic and conceal the true source of their operations. This type of infrastructure allows ordinary home routers to be used as intermediary nodes in long-running espionage campaigns.