Regulation

Asus routers vulnerable to command execution through malicious VPN files

Two critical security flaws in Asus routers allow attackers to run arbitrary commands, with one vulnerability rated 9.4 on the CVSS severity scale.

1 min read
Malicious VPN config files can let attackers run commands on Asus routers

Asus has disclosed a pair of serious vulnerabilities affecting its routers. The more severe of the two—a flaw involving specially crafted VPN client configuration files—carries a CVSS 4.0 score of 9.4, which Asus classifies as critical.

An attacker or malicious user could exploit the first vulnerability by uploading a malformed VPN configuration file through the router's web management interface, potentially gaining the ability to "execute arbitrary commands." The second vulnerability stems from debug code that was not disabled in production firmware, creating a separate attack vector. This flaw could permit an attacker to circumvent security protections, activate Telnet access, and possibly execute commands "with root privileges" on connected devices.

Asus advises users to "only import VPN client configuration files from trusted sources." The two vulnerabilities have been assigned CVE-2026-14157 and CVE-2026-13313, scoring 9.4 and 8.9 respectively on the CVSS 4.0 scale. Firmware version 3.0.0.6_102 is affected by both flaws, while versions 3.0.0.4_386 and 3.0.0.4_388 are vulnerable to the Telnet-related bug.

Source: Tom's Hardware · Reporting supplemented by The Silicon Ledger staff.