Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
ID: 3fbc0add-0f11-5b4c-ab95-452201ca2571
STIX ID: report--3fbc0add-0f11-5b4c-ab95-452201ca2571
Feed Name: Cyber Press
ASUS released a security advisory for a critical firmware vulnerability (CVE-2026-13385) in the UU feature of ASUSWRT for CN‑SKU router models that allows a network MITM attacker to supply spoofed responses causing the router to download and execute arbitrary commands. Affected firmware branches include 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102; users are urged to update immediately and harden edge network controls. ASUS also published related advisories (CVE-2026-11851 and CVE-2026-12960) covering information disclosure and an Android app issue, and reported no known active exploitation at disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
