CVE-2026-13385: ASUS Router
Critical severity, CVSS 9.5. EPSS: 0.1% chance of exploitation in the next 30 days.
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Affected products
- ASUS Router: version 3.0.0.4_386 series only; version 3.0.0.4_388 series only; version 3.0.0.6_102 series only
Published 2026-07-15. Last modified 2026-07-29.