CVE-2026-14911: ASUS Router

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Router: version 3.0.0.6.102 series only

Published 2026-10-07. Last modified 2026-10-07.