Externally Controlled Format String Vulnerability in ASUS Router Products
CVE-2026-14157

9.4CRITICAL

Key Information:

Vendor

Asus

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-14157?

A vulnerability exists in ASUS Router modules that allows a remote authenticated user to manipulate format strings, potentially leading to arbitrary command execution. This risk arises when crafted files are uploaded via the web management interface, allowing unauthorized access and control over affected devices. Users must remain vigilant and apply security updates as they become available to mitigate this risk.

Affected Version(s)

Router 3.0.0.6_102 series

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.