CVE-2026-13313: ASUS Router

High severity, CVSS 8.9. EPSS: 0.7% chance of exploitation in the next 30 days.

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Router: version 3.0.0.4_386 series only; version 3.0.0.4_388 series only; version 3.0.0.6_102 series only

Published 2026-10-01. Last modified 2026-10-02.