Predictable Seed Vulnerability in ASUS RT-BE57 Router
CVE-2026-19396

7.7HIGH

Key Information:

Vendor

Asus

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-19396?

A security flaw has been discovered in the ASUS RT-BE57 router that allows an unauthenticated nearby user to exploit a predictable seed in the pseudo-random number generator (PRNG). This vulnerability affects the generation of IFTTT pairing tokens, enabling malicious users to derive the pairing token. By observing values during an administrator-initiated IFTTT pairing session, attackers can potentially read or modify router settings. For further details, please refer to the ASUS Security Advisory on router firmware updates.

Affected Version(s)

Router 3.0.0.6_102 series

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.