Skip to content
GADGETNWIDGETTechnology. With a purpose.
Computing / Article

ASUS patches critical router flaw hidden in malicious VPN files

ASUS router updates address a critical VPN-profile command-injection flaw and a second bug that can enable Telnet with root access.

Gadget N Widget editorial · Published October 4, 2026

Black ASUS RT-BE92U Wi-Fi router with four antennas on a wooden table

ASUS has released router firmware updates for two serious security flaws that could let an attacker run commands on affected hardware. One weakness involves malicious VPN configuration files, while the other can expose a hidden Telnet service with root-level privileges.

The most important action is straightforward: owners of ASUS routers should check for new firmware through the router’s administration page or the support page for their exact model. The vulnerabilities are tracked as CVE-2026-14157 and CVE-2026-13313.

The VPN-file flaw is rated critical

CVE-2026-14157 affects the way certain ASUS firmware handles VPN client configuration files. ASUS routers can act as VPN clients, allowing every device on a home network to send traffic through a VPN service. Setting that up often requires importing an OpenVPN profile supplied by the VPN provider.

According to Tom’s Hardware, a specially crafted configuration file can be interpreted in a way that permits arbitrary command execution. ASUS assigned the flaw a CVSS 4.0 severity score of 9.4 out of 10, placing it in the critical range.

This does not mean that simply using a VPN app on a phone or laptop exposes the router. The vulnerable path involves importing a VPN profile into the router’s own web-management interface. Exploitation therefore depends on an administrator uploading a malicious file or an attacker first obtaining authenticated access to the router.

ASUS advises customers to import VPN profiles only from trusted sources. If a VPN provider directs users to download a configuration from an unfamiliar mirror, email attachment or forum post, it is safer to obtain a fresh copy from the provider’s official account page.

A second flaw can enable Telnet with root access

CVE-2026-13313 involves debug functionality that remained available in affected firmware. A logged-in attacker can bypass checks, enable the router’s Telnet service and potentially execute commands with root privileges. ASUS rates this issue at 8.9 out of 10 under CVSS 4.0.

Root access represents control over the router’s operating system. Depending on the attack, that could allow someone to change network settings, redirect traffic, monitor connected devices or install persistent malicious components. The published advisory does not establish that every possible outcome has occurred in real-world attacks, but the level of access makes prompt patching important.

The two flaws have different technical paths, yet both reinforce the same point: the router’s administrator account is a high-value credential. Anyone who still uses a default, reused or easily guessed admin password should replace it.

Which ASUS routers are affected?

ASUS identifies affected firmware branches rather than publishing one simple consumer-facing model list. The 3.0.0.6_102 series is associated with both vulnerabilities. The older 3.0.0.4_386 and 3.0.0.4_388 branches are also affected by the Telnet weakness.

That naming makes it important to check the exact product support page instead of assuming a router is safe because its retail name does not appear in a news report. Firmware availability varies by model and region.

To check the installed version, sign in to the router locally and look for the firmware or administration section. ASUS routers commonly use the ASUS Router mobile app or the router.asus.com web interface, but menu names can vary. Owners should confirm that the update comes from ASUS and avoid firmware files shared through third-party download sites.

What ASUS router owners should do now

Updating firmware is the priority. After the installation and reboot, owners should verify that their internet connection, Wi-Fi networks and VPN settings still work as expected.

ASUS also recommends a strong, unique administrator password containing at least 10 characters and a mixture of uppercase letters, numbers and symbols. Length matters as much as complexity, so a longer password that is not reused elsewhere is preferable.

Additional precautions can reduce exposure:

  • Disable remote web administration unless it is genuinely needed.
  • Import VPN profiles only from the official VPN provider.
  • Remove unknown administrator accounts and review recent configuration changes.
  • Avoid running untrusted scripts or tools on devices connected to the local network.
  • Back up the router configuration after updating and confirming that it is clean.

These steps do not replace the firmware patch, but they make it harder for an attacker to reach the vulnerable management functions.

End-of-life routers need special attention

ASUS says routers that have reached end of life will not receive new firmware. Strong passwords and safer configuration practices can lower risk, but they cannot remove a vulnerability from unsupported software.

If an affected model has no patch and no longer receives security updates, replacement is the safer long-term decision. When shopping, buyers should check the manufacturer’s support policy and avoid treating Wi-Fi speed alone as the measure of a router’s useful life.

Why this update matters

A home router sits between every connected device and the wider internet. Phones, computers, cameras, televisions and smart-home products may all depend on it, so a compromised router can create risks beyond the router itself.

Neither vulnerability is described as an unauthenticated, automatic takeover of every ASUS router on the internet. Both involve access to management functions: the critical flaw uses a crafted VPN file, and the Telnet flaw requires an authenticated attacker. That limitation is reassuring, but it is not a reason to delay an available patch. Stolen credentials and social-engineering tricks are common ways to turn an access requirement into a practical attack.

ASUS maintains its current notices on the company’s Product Security Advisory page. Owners who are unsure about their model should search the ASUS support site using the model number printed on the router’s label.

Featured image: ASUS RT-BE92U router product photo, courtesy of ASUS.