Active Debug Code Vulnerability in ASUS Routers
CVE-2026-13313

8.9HIGH

Key Information:

Vendor

Asus

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-13313?

A vulnerability exists in certain ASUS router models due to the presence of Active Debug Code. This flaw permits a remote authenticated user to craft specific HTTP requests that can bypass the router's security measures. When exploited, this can enable the Telnet service, granting the attacker the ability to execute arbitrary commands with root privileges. Consequently, this poses a significant risk, as it may compromise not only the targeted router but potentially other devices connected to the same network. For comprehensive details and mitigation steps, refer to the ASUS Security Advisory.

Affected Version(s)

Router 3.0.0.4_386 series

Router 3.0.0.4_388 series

Router 3.0.0.6_102 series

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.