Vulnary
← back to the feed
Critical· 9.5official fix available

CVE-2026-13385

Certain ASUS routers have a flaw that lets a remote attacker trick the device into downloading and running malicious commands. The vulnerability is due to improper validation of integrity checks and certificates. A firmware update from ASUS fixes the issue.

publishedJul 15, 2026
last modifiedJul 29, 2026
sourcesNVD
severity · cvss
9.5
critical · how bad it is
exploitation · epss
<1%
4th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 28, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

ASUS router models referenced in the ASUS Security Advisory's Security Update for ASUS Router Firmware section.

02

Real-world impact

An attacker could remotely control the router, download and execute arbitrary commands, potentially compromising the network and devices connected to it.

03

Why this severity

The CVSS score of 9.5 reflects the high impact of the vulnerability: it allows remote attackers to execute arbitrary commands with no authentication, leading to full compromise of the router and the network.

04

What to do about it

official fix available
recommended steps
  1. 01Follow the instructions in the ASUS Security Advisory to download and install the latest firmware update for your router.
  2. 02Restart the router after the update.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 15, 2026 · 15d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 29, 2026 · 16h ago
    Advisory updated
    The NVD record was last revised.
  3. Jul 29, 2026 · 15h ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsPresent
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →