Published on July 22, 2026

Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands


Severity

Critical

Detail

ASUS has disclosed a critical security vulnerability, tracked as CVE-2026-13385, affecting multiple ASUS router firmware versions. The flaw stems from improper validation of network communications and could allow a remote attacker to execute arbitrary commands through a man-in-the-middle (MITM) attack.

According to ASUS, the vulnerability affects firmware branches 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102. An attacker positioned between the router and a trusted service can manipulate network traffic and inject malicious commands, potentially gaining unauthorized control over affected devices.

Successful exploitation may result in complete router compromise, allowing attackers to intercept network traffic, perform DNS hijacking, modify router configurations, and establish persistent access. In enterprise environments, compromised routers could also facilitate lateral movement within internal networks or be leveraged as part of larger botnet operations.

Security researchers noted that MITM-based attacks are particularly effective on untrusted or compromised networks, such as public Wi-Fi or environments where network traffic can be intercepted. ASUS has addressed the issue through updated firmware releases and recommends users install the latest available firmware immediately.

CVE IDSummaryCVSS Score
CVE-2026-13385Improper validation of network communications in ASUS router firmware allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack, potentially leading to device compromise and unauthorized network access.Critical

Affected Products

The vulnerability affects ASUS routers running the following firmware branches:

  • ASUS Router Firmware 3.0.0.4_386
  • ASUS Router Firmware 3.0.0.4_388
  • ASUS Router Firmware 3.0.0.6_102

Recommendation

Organizations and ASUS router administrators are strongly advised to take the following actions to reduce the risk of compromise:

  • Upgrade affected routers to the latest firmware released by ASUS that addresses CVE-2026-13385.
  • Disable remote administration if it is not required and restrict management access to trusted networks only.
  • Implement network segmentation to limit the impact of a compromised network device.
  • Monitor routers for unauthorized configuration changes, unexpected DNS modifications, and unusual outbound network traffic that may indicate compromise.
  • Avoid managing routers over untrusted networks and use encrypted management connections whenever possible.

Source

https://gbhackers.com/critical-asus-router-flaw/