CVE-2026-14157

Summary

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.

Affected Software

VendorProductVersion RangeStatus
ASUSRouter3.0.0.6_102 seriesaffected

Weaknesses

  • CWE-134: CWE-134: Use of Externally-Controlled Format String

References