The two flaws
Tom's Hardware reports that a "crafted VPN client configuration file" uploaded through an Asus router's web management interface can let an attacker "execute arbitrary commands." The CVE record, as mirrored by Tenable, describes the use of an externally controlled format string in the ASUS router modules, allowing a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface. That is CVE-2026-14157.
In plain terms, a format string bug means text that should be treated as data gets interpreted as instructions. Tom's Hardware describes it the same way: crafted text inside the uploaded file is read as formatting instructions.
The second flaw is CVE-2026-13313. It is an Active Debug Code vulnerability. A remote authenticated user can send a crafted HTTP request to bypass security mechanisms and enable Telnet. That allows arbitrary commands with root privileges, potentially affecting other devices connected to the router.
The two are separate:
| CVE-2026-14157 | CVE-2026-13313 | |
|---|---|---|
| Weakness | Format string handling of an uploaded file | Active debug code (CWE-489) |
| Trigger | Crafted file uploaded via web management | Crafted HTTP request enabling Telnet |
| CVSS 4.0 | 9.4 (Critical) | 8.9 (High) |
| Affected firmware series | 3.0.0.6_102 | 3.0.0.4_386, 3.0.0.4_388, 3.0.0.6_102 |
The 9.4 score for the first flaw appears in the Tenable listing. Cybernews and threat-intelligence trackers likewise report the second at 8.9, covering the 3.0.0.4_386, 3.0.0.4_388 and 3.0.0.6_102 series.
How serious is it?
The headline numbers look alarming, but the details matter. Tenable's listing shows the CVSS 4.0 vector for CVE-2026-14157 includes PR:H, meaning high privileges are required. A CVSS 3.1 score of 9.8 is also listed with no privileges required, but the 4.0 vector is the one behind the 9.4 figure. For CVE-2026-13313, the published vector also carries PR:H and a high attack complexity rating.
In practice, an attacker generally needs to be logged in to the router's admin interface first, or must trick an administrator into importing a bad file. Tom's Hardware notes Asus warns that "attackers may use social engineering to trick administrators." That is my reading of the scoring. It is not a claim that the bugs are harmless. Home routers often have weak or reused admin passwords, and some owners expose the admin page to the internet.
As for real-world use, SecurityOnline says no working exploit code has been published and no active exploitation has been confirmed. I could not verify whether the admin interface is reachable from the internet on affected default configurations. Exposure depends on how each router is set up.
Who is affected
Only routers that import VPN client profiles are in play for the first flaw. Asus's own support guide covers the workflow. You sign in to the router's web interface, open the VPN section, add a profile, choose OpenVPN, upload the provider's .ovpn file, and create the profile. Asus also notes that newer firmware calls the client feature VPN Fusion.
The router acts as the VPN client so that devices that can't run VPN software, such as smart TVs and set-top boxes, can be covered. That makes it a handy feature, and also a handy place to feed in a booby-trapped file.
The risk applies to files imported into the router. It does not apply to VPN apps on a Windows PC or phone. The vulnerable code is in the router's management interface.
Asus names firmware series, not models, so you can't tell from the advisory text alone whether your router is affected. Check your exact model and the firmware version shown in the admin page against Asus's security advisory and your model's support page. I could not retrieve a model-by-model list or fixed build numbers from Asus's advisory page, so I won't name any.
What to do
- Update the firmware. Find your model's download page on Asus's support site and install the latest release. Asus's advisory page tells customers to keep products updated and apply the latest firmware patches. Check the "Security Update for ASUS Router Firmware" section of the advisory for your model.
- Import VPN profiles only from sources you trust. Tom's Hardware reports Asus advises importing VPN client configuration files only from trusted sources. Get the file directly from your VPN provider. Don't use one sent by a stranger, a forum post or a "helpful" friend.
- Set a strong, unique admin password. Asus recommends at least 10 characters mixing uppercase letters, numbers and symbols. Because both flaws require authentication, this is a real barrier. It is not a substitute for patching.
- Avoid untrusted scripts and tools on your local network. Asus advises against running scripts, tools or commands from untrusted sources on devices in your network.
- Check Telnet. Telnet shouldn't be enabled on a home router you didn't set up for it. If you find it on and don't know why, treat the router as suspect, change credentials, and update.
- Retire end-of-life routers. Tom's Hardware says Asus won't release new firmware for them. For those, Asus advises strong, unique login and Wi-Fi passwords. Replacement is the better answer.
Context
Tom's Hardware points out that the VPN import path was also the entry point for CVE-2024-0401, disclosed in 2024 by VulnCheck, which used a crafted OVPN profile. I haven't independently verified that earlier case. Even so, the pattern is familiar: router management pages that parse user-supplied files are a recurring source of bugs.
The same Asus update cycle also covers 13 motherboards. That flaw involves improper initialization, and a physically proximate user could read or write arbitrary memory by inserting a specially crafted device. It needs physical access and is a separate matter from the router bugs. Tom's Hardware lists the BIOS fixes as version 1502 for the WS Z390 Pro and 2203 for the other 12 boards.
Bottom line
- Two separate authenticated command-execution flaws in Asus router firmware were published on October 1, 2026, scored 9.4 and 8.9 on CVSS 4.0.
- Exploiting them generally requires admin-interface access or tricking an administrator, but a compromised router puts every device behind it at risk.
- Check your model and firmware, patch, use only trusted VPN files, and lock down the admin login.
References
- Malicious VPN config files can let attackers run commands on Asus routers Tom's Hardware · 2026-10-03T12:30:00+00:00
- CVE-2026-14157<!-- --> | Tenable® tenable.com
- (VPN) How to set up VPN Client in ASUS router (Web GUI)? | Official Support | ASUS UK asus.com