CVE-2026-19396: ASUS Router
High severity, CVSS 7.7. EPSS: 0.1% chance of exploitation in the next 30 days.
A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via observed values from an administrator-initiated IFTTT pairing session.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Affected products
- ASUS Router: version 3.0.0.6_102 series only
Published 2026-10-07. Last modified 2026-10-07.