Asus has released firmware updates for several routers that close a critical hole. A crafted VPN client configuration file uploaded through an Asus router's web management interface can let an attacker execute arbitrary commands. That applies to the user themselves, but also to an attacker who is already logged in. A second, separate bug stems from debug code left active. It lets an attacker bypass security checks and enable Telnet, which may allow commands to run with root privileges. Devices connected to the router could be affected too.
The two flaws are tracked as CVE-2026-14157 and CVE-2026-13313. They score 9.4 and 8.9 out of 10 on the CVSS 4.0 scale. Asus names firmware series rather than models: 3.0.0.6_102 is affected by both bugs, while the 3.0.0.4_386 and 3.0.0.4_388 series are also affected by the Telnet one.
How the flaw arises
A router can act as a VPN client when you set it up with a configuration file from a VPN provider. Things go wrong when crafted text inside the file is read as formatting instructions instead of plain data. So the risk applies to owners who import VPN files directly into the router, not to VPN apps on a laptop or phone. The Telnet bug requires the service to be enabled first before commands can be run that could affect the network.
Asus advises importing VPN configuration files only from trusted sources. It also recommends a strong, unique admin password with at least ten characters mixing upper- and lowercase letters, numbers, and symbols, and avoiding scripts, tools, or commands from untrusted sources on anything in your local network. Attackers may use social engineering to trick administrators into running them.
A familiar weak spot
The VPN bug uses the same entry point as CVE-2024-0401, which VulnCheck disclosed in 2024 and which relied on a crafted OVPN profile. That makes config file import through the admin page a recurring weak point on Asus devices. As a popular brand, Asus is also a likely target: the AyySSHush campaign used authentication bypasses, brute-force logins, and a command injection flaw (CVE-2023-39780) to backdoor more than 9,000 routers, and the backdoor even survived firmware updates.
13 motherboards affected too
Alongside the router fixes came one for 13 motherboards. A physically present attacker could read or write arbitrary system memory by plugging in a specially crafted device. Many Z390 and C246 boards are affected, and the flaw is rated high at 7.0 out of 10, lower than the router bugs. The fix is BIOS 1502 for the WS Z390 Pro and 2203 for the other twelve boards. You can find the updates on Asus's support page or your product's page. Routers that have reached end of life won't get new firmware. For those, Asus advises strong, unique passwords for login and Wi-Fi.