CVE-2026-16528

Summary

Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

Affected Software

VendorProductVersion RangeStatus
ASUSRouter3.0.0.4.386 seriesaffected
ASUSRouter3.0.0.4.388 seriesaffected
ASUSRouter3.0.0.6.102 seriesaffected

Weaknesses

  • CWE-532: CWE-532: Insertion of Sensitive Information into Log File

References