Tuesday, September 8, 2026

Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands

ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack.

This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102.

Critical ASUS Router Flaw

According to the ASUS Product Security Advisory, the vulnerability arises from improper validation of network communications. This allows an attacker positioned between the router and a legitimate service to manipulate traffic and inject harmful commands.

If successfully exploited, this vulnerability could grant attackers unauthorized control over affected routers, potentially leading to complete device compromise, traffic interception, DNS hijacking, and lateral movement within internal networks.

Given the crucial role that routers play in network infrastructure, such exploitation could also enable large-scale botnet recruitment or provide persistent access to advanced threat actors.

Security researchers warn that MITM-based exploitation significantly lowers the barriers for attackers operating on compromised or untrusted networks, such as public Wi-Fi or scenarios involving ISP-level interception.

ASUS stated that it adheres to Coordinated Vulnerability Disclosure (CVD) practices and collaborates closely with security researchers and industry partners, following frameworks like ISO 29147:2018 and ISO 30111:2019.

As a CVE Numbering Authority (CNA) and a member of FIRST, ASUS is committed to enhancing its vulnerability management lifecycle and encourages users to apply security updates promptly.

The company has released patched firmware versions that address CVE-2026-13385 and related vulnerabilities, strongly advising users to upgrade to the latest firmware releases.

In addition to this critical router vulnerability, ASUS has published various security bulletins covering a range of vulnerabilities across its ecosystem, including system utilities, drivers, and mobile applications.

These vulnerabilities highlight the broader attack surface across ASUS software components and underscore the importance of comprehensive patch management and continuous monitoring.

Both organizations and individual users are urged to apply firmware updates immediately, turn off remote administration where it is not needed, and implement network segmentation to reduce exposure.

For high-risk environments, monitoring for unusual DNS changes, unauthorized configuration modifications, and abnormal outbound traffic patterns can help detect potential compromises.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support

A newly identified ransomware-as-a-service operation, Panzer, has surfaced with...

Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA

Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

Related Articles

Recent News