CVE-2026-14157
9.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ASUS | Router | 3.0.0.6_102 series | affected |
Weaknesses
- CWE-134: CWE-134: Use of Externally-Controlled Format String
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.