Junglewise Threat Intelligence

CVE-2026-12960: ASUS Router App improper export of Android components

CVE-2026-12960 · Severity: info · CVSS 6 · Published 2026-07-03

Vendors: ASUS.

Executive brief

The ASUS Router app for Android contains a security flaw that allows other malicious apps installed on the same smartphone to interfere with its operations. Specifically, a rogue app could force the ASUS Router app to open a web link of the attacker's choosing. This could be used in phishing attacks to trick users into visiting fraudulent websites while appearing to be within a trusted ASUS application.

Technical details

The ASUS Router Android application suffers from an Improper Export of Android Application Components (CWE-926). A specific component within the app is exported without proper access controls, allowing third-party applications on the same device to send a crafted Intent. This Intent can be used to trigger the ASUS Router app to open a specified URL. While the primary impact is localized to the device (AV:L) and requires user interaction (UI:P), it can be leveraged for phishing or to bypass security boundaries by launching the browser within the context of a trusted application. The vulnerability is present in versions up to and including 1.0.0.9.71.

Affected products

  • ASUS Router app <= 1.0.0.9.71

Timeline

  • 2026-07-03: advisory
  • 2026-07-03: disclosed

References