Malicious VPN config files can let attackers run commands on Asus routers
What happened
Malicious VPN (a service that routes a connection through another network) config files can let attackers run commands on Asus routers, according to Tom's Hardware. Until routers on Asus’s 3.0.0.6_102 firmware are updated, the company says not to import untrusted VPN files. A “crafted VPN client configuration file” uploaded by the user or a logged-in attacker via an Asus router’s web management interface can allow an adversary to “execute arbitrary commands,” a critical security risk the company has acted to patch . ASUS is an electronics company based in Taipei.
A second, separate bug, which operates with debug code left active, allows the attacker to bypass security checks in order to enable Telnet and may allow commands to be run “with root privileges,” potentially affecting devices connected to the router. Asus recommends that users “only import VPN client configuration files from trusted sources.”
The two CVEs, CVE-2026-14157 (the public catalogue number for a specific software flaw) and CVE-2026-13313, score 9.4 and 8.9 out of 10 on the Common Vulnerability Scoring System (CVSS) 4.0 scale, which measures vulnerability severity. Asus names firmware series rather than models: 3.0.0.6_102 for both bugs, with the 3.0.0.4_386 and 3.0.0.4_388 series also affected by the Telnet one.
Sources & evidence
- Tom's Hardware Reporting source
Malicious VPN config files can let attackers run commands on Asus routers ↗
https://www.tomshardware.com/tech-industry/cyber-security/malicious-vpn-config-files-can-let-attackers-run-commands-on-asus-routers-companys-patch-also-fixes-a-bug-that-lets-a-logged-in-attacker-switch-on-telnet-with-root-access