CVE-2026-12960: ASUS Router App

Medium severity, CVSS 6.0. EPSS: 0.2% chance of exploitation in the next 30 days.

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Router App: up to and including 1.0.0.9.71

Published 2026-07-03. Last modified 2026-09-17.