Asus patches two critical router firmware flaws tied to VPN config files
Asus has issued firmware updates for two critical vulnerabilities affecting its routers. One, CVE-2026-14157 (CVSS 9.4), lets an attacker who uploads a crafted VPN client configuration file through the router's web interface execute arbitrary commands. The other, CVE-2026-13313 (CVSS 8.9), exploits leftover debug code to bypass security checks, enable Telnet, and potentially run commands with root privileges, affecting firmware series 3.0.0.6_102, 3.0.0.4_386 and 3.0.0.4_388.