Cross-Site Scripting Vulnerability in ASUS Router Modules
CVE-2026-14911
9.3CRITICAL
What is CVE-2026-14911?
ASUS routers contain a vulnerability due to improper neutralization of input during web page generation, known as Cross-Site Scripting. This flaw allows a remote attacker to manipulate the DOM, modify the settings of the router, and potentially trigger a denial-of-service condition. The vulnerability is exploited when an authenticated user accesses a specially crafted URL. Users are encouraged to apply the latest firmware updates as detailed in the ASUS Security Advisory.
Affected Version(s)
Router 3.0.0.6.102 series