Executive brief
The ASUS Router app for Android contains a security flaw that allows other malicious apps installed on the same smartphone to interfere with its operations. Specifically, a rogue app could force the ASUS Router app to open a web link of the attacker's choosing. This could be used in phishing attacks to trick users into visiting fraudulent websites while appearing to be within a trusted ASUS application.
Technical details
The ASUS Router Android application suffers from an Improper Export of Android Application Components (CWE-926). A specific component within the app is exported without proper access controls, allowing third-party applications on the same device to send a crafted Intent. This Intent can be used to trigger the ASUS Router app to open a specified URL. While the primary impact is localized to the device (AV:L) and requires user interaction (UI:P), it can be leveraged for phishing or to bypass security boundaries by launching the browser within the context of a trusted application. The vulnerability is present in versions up to and including 1.0.0.9.71.
Affected products
- ASUS Router app <= 1.0.0.9.71
Timeline
- 2026-07-03: advisory
- 2026-07-03: disclosed