CVE-2026-16528: ASUS Router

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Router: version 3.0.0.4.386 series only; version 3.0.0.4.388 series only; version 3.0.0.6.102 series only

Published 2026-10-07. Last modified 2026-10-07.