CVE-2026-19386: ASUS Router

Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Router: version 3.0.0.6.102 series only

Published 2026-10-07. Last modified 2026-10-08.