CVE-2026-16528
8.4
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Summary
Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ASUS | Router | 3.0.0.4.386 series | affected |
| ASUS | Router | 3.0.0.4.388 series | affected |
| ASUS | Router | 3.0.0.6.102 series | affected |
Weaknesses
- CWE-532: CWE-532: Insertion of Sensitive Information into Log File
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.