CVE-2026-13313
8.9
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ASUS | Router | 3.0.0.4_386 series | affected |
| ASUS | Router | 3.0.0.4_388 series | affected |
| ASUS | Router | 3.0.0.6_102 series | affected |
Weaknesses
- CWE-489: CWE-489: Active Debug Code
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.