CVE-2026-14157: ASUS Router
Critical severity, CVSS 9.4. EPSS: 0.8% chance of exploitation in the next 30 days.
Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.
Affected products
- ASUS Router: version 3.0.0.6_102 series only
Published 2026-10-01. Last modified 2026-10-02.