ASUS Router Firmware Vulnerability CVE-2026-14157 Rated Critical
At a glance
- CVE-2026-14157 affects ASUS Router firmware 3.0.0.6_102 series.
- The vulnerability enables remote command execution by authenticated users.
- A patch is available, and no public exploit is known as of October 1, 2026.
A critical security flaw has been identified in certain ASUS Router firmware versions, allowing authenticated remote users to execute commands through the web management interface. The issue is tracked as CVE-2026-14157 and was published on October 1, 2026.
The vulnerability affects the 3.0.0.6_102 series of ASUS Router firmware. According to available reports, exploitation requires authentication and involves uploading a specially crafted file to the device's web management portal.
Security documentation assigns a CVSS score of 9.4 to CVE-2026-14157, categorizing it as a critical threat. This assessment is based on the potential for remote command execution if the vulnerability is exploited by an authenticated user.
As of the publication date, there is no known public exploit or proof-of-concept code available for this vulnerability. This status reduces immediate risk from automated attacks, but users are still advised to take action to secure their devices.
What the numbers show
- CVE-2026-14157 was published and last updated on October 1, 2026.
- The vulnerability has a CVSS score of 9.4.
- It affects ASUS Router firmware version 3.0.0.6_102 series.
According to security advisories, a patch addressing CVE-2026-14157 is available. Users are encouraged to update their firmware to a version beyond the affected 3.0.0.6_102 series to mitigate the risk.
In addition to updating firmware, users are advised to restrict access to the router's web management interface. Limiting access can help prevent unauthorized attempts to exploit the vulnerability, even if authentication credentials are compromised.
The vulnerability was documented in multiple security databases and reports, but no official advisory from ASUS was located at the time of reporting. Information about the patch and mitigation steps comes from third-party security summaries.
Ongoing monitoring of security databases is recommended for users of affected ASUS routers. Applying available updates and following recommended security practices can help reduce exposure to this and similar vulnerabilities.
* This article is based on publicly available information at the time of writing.