CVE-2026-13385: Critical severity ASUS ASUS Router Firmware vulnerability
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13385?
CVE-2026-13385 has a critical severity rating of 9.5.
How does CVE-2026-13385 impact ASUS router users?
CVE-2026-13385 allows a remote man-in-the-middle attacker to execute arbitrary commands on affected ASUS routers.
What models are affected by CVE-2026-13385?
CVE-2026-13385 affects certain models of ASUS routers that are running the vulnerable firmware.
How do I fix CVE-2026-13385?
To mitigate CVE-2026-13385, users should update their ASUS router firmware to the latest version provided by ASUS.
What can be done to protect against CVE-2026-13385?
Users are advised to regularly check for firmware updates and apply them promptly to protect against CVE-2026-13385.