Asus patches critical flaws in routers and motherboards
Asus released fixes for two critical router vulnerabilities: uploading a crafted VPN client configuration file allows arbitrary command execution, while a second bug via active debug code enables Telnet with root privileges. The flaws are rated 9.4 and 8.9 on CVSS 4.0. A separate high-severity flaw affects 13 Z390 and C246 motherboards.
- CVE-2026-14157: malicious VPN config enables command execution, CVSS 9.4
- CVE-2026-13313: debug code opens Telnet with root privileges, CVSS 8.9
- Affected firmware: 3.0.0.6_102, 3.0.0.4_386 and 3.0.0.4_388
- Motherboard flaw affects 13 Z390 and C246 boards, needs physical access, CVSS 7.0
Read next
Security