Executive brief
A security vulnerability has been identified in the web management interface of several ASUS router models. This flaw allows an attacker to execute unauthorized system commands if they have administrative access or can trick an administrator into performing a specific action. Successful exploitation could lead to a complete takeover of the router, potentially allowing attackers to intercept network traffic, disrupt internet connectivity, or access connected devices.
Technical details
This vulnerability (CWE-78) is an OS command injection flaw located within the web management interface of ASUS routers. The root cause is improper neutralization of special elements used in an OS command, specifically via a crafted parameter. While the primary description indicates an authenticated administrator is required, historical analysis notes suggest a potential Cross-Site Request Forgery (CSRF) component (CWE-352) that could allow an unauthenticated attacker to trigger the command execution if a logged-in administrator visits a malicious site. An attacker can achieve full system-level command execution on the device. ASUS has released firmware updates to address this issue, and users are advised to update to versions beyond 3.0.0.6_102.
Affected products
- ASUS Router Firmware up to (including) 3.0.0.6_102
Timeline
- 2026-03-25: disclosed
- 2026-03-26: advisory
- 2026-05-13: other: Advisory updated to clarify OS command injection details and update CVSS scores.