Junglewise Threat Intelligence

CVE-2026-13385: ASUS Router remote command execution via improper certificate validation

CVE-2026-13385 · Severity: info · CVSS 9.5 · Published 2026-07-15

Vendors: ASUS.

Executive brief

A security vulnerability exists in several ASUS router models that could allow an attacker to take complete control of the device. By intercepting the router's communication, an attacker can trick the device into downloading and running malicious commands from a fake server. This could lead to the theft of personal data, monitoring of internet traffic, or a total loss of network security for the home or business.

Technical details

The vulnerability stems from Improper Certificate Validation (CWE-295) and Improper Validation of Integrity Check Value (CWE-354) within the firmware update or communication modules of affected ASUS routers. A remote attacker positioned as a man-in-the-middle (MITM) can bypass security checks by using a spoofed server. Because the router fails to properly verify the server's identity and the integrity of the downloaded data, the attacker can force the device to download and execute arbitrary commands with high privileges. The vulnerability affects firmware versions in the 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series.

Affected products

  • ASUS Router Firmware 3.0.0.4_386 series
  • ASUS Router Firmware 3.0.0.4_388 series
  • ASUS Router Firmware 3.0.0.6_102 series

Timeline

  • 2026-07-14: disclosed: CVE record published by ASUS
  • 2026-07-15: advisory: NVD publication date

References

Related threats