CVE-2026-13385
Certain ASUS routers have a flaw that lets a remote attacker trick the device into downloading and running malicious commands. The vulnerability is due to improper validation of integrity checks and certificates. A firmware update from ASUS fixes the issue.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
ASUS router models referenced in the ASUS Security Advisory's Security Update for ASUS Router Firmware section.
Real-world impact
An attacker could remotely control the router, download and execute arbitrary commands, potentially compromising the network and devices connected to it.
Why this severity
The CVSS score of 9.5 reflects the high impact of the vulnerability: it allows remote attackers to execute arbitrary commands with no authentication, leading to full compromise of the router and the network.
What to do about it
- 01Follow the instructions in the ASUS Security Advisory to download and install the latest firmware update for your router.
- 02Restart the router after the update.
NVD-referenced vendor advisory
Timeline
- Jul 15, 2026 · 15d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 16h agoAdvisory updatedThe NVD record was last revised.
- Jul 29, 2026 · 15h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.