Skip to content

Asus Patches Critical Router Flaws Tied to VPN Config Files

Asus has rushed out firmware fixes for two severe router vulnerabilities, one tied to malicious VPN configuration files and another that can quietly switch on Telnet with root access.

A sleek home technology setup featuring a router, glass decoration, and television.
Photo: Jaycee300s / Pexels

Asus has shipped firmware updates to close two serious security holes in its routers, one of which the company itself rates as critical at 9.4 out of 10 on the CVSS 4.0 scale. The flaw lets an attacker slip malicious code into a router through something surprisingly mundane: a VPN client configuration file uploaded through the device’s own web management interface. A second, separate bug can let a logged-in attacker secretly enable Telnet and run commands with root privileges, potentially putting every device on the home network at risk.

How the VPN config file attack works

Many Asus routers can act as a VPN client themselves, letting the whole household route traffic through a VPN service without installing anything on individual devices. To set that up, owners import a configuration file supplied by their VPN provider through the router’s admin panel. According to Asus, the problem is that text inside a specially crafted version of that file can be interpreted as formatting instructions instead of being treated as plain data. That mix-up is what lets an attacker execute arbitrary commands on the router, tracked as CVE-2026-14157.

It’s worth being clear about what this does and doesn’t affect. This isn’t a risk for people simply running a VPN app on their laptop or phone. It only applies to owners who import VPN configuration files directly into the router hardware itself.

A second bug: Telnet with root access

The other patched issue, CVE-2026-13313, scores 8.9 on the same scale and stems from leftover debug code. It allows an attacker who is already logged in to bypass security checks and switch on Telnet, an old remote-access protocol that, once active, can let commands run with root privileges. Asus says this could affect any devices connected to the router, not just the router itself, which makes it a meaningful risk for anyone managing a household’s connected gadgets, smart home gear, or a small office network.

Which routers and firmware are affected

Asus identified the affected firmware by series rather than by individual router model. Firmware series 3.0.0.6_102 is affected by both bugs, while the Telnet issue also extends to the 3.0.0.4_386 and 3.0.0.4_388 series. Owners should check their router’s firmware version against Asus’s support page or their specific product page to see whether an update is available. Routers that have already reached end of life won’t receive a fix; for those, Asus’s fallback advice is to use strong, unique login and Wi-Fi passwords to limit exposure.

This isn’t the first time Asus’s config-file import process has been a weak point. The VPN bug uses the same entry point as a 2024 vulnerability found by VulnCheck, which exploited a crafted OVPN profile. The repeat appearance suggests the web admin page’s handling of imported VPN files is a recurring soft spot worth watching for future disclosures too. Asus routers have also been a target before in real-world attacks: the AyySSHush campaign combined authentication bypasses, brute-force logins, and a separate command-injection flaw to backdoor more than 9,000 routers, with the backdoor surviving even after firmware updates.

A separate, lower-severity motherboard issue

Alongside the router fixes, Asus also patched a flaw affecting 13 motherboards, mostly in the Z390 and C246 lines. It’s rated high severity at 7.0 out of 10, notably lower than the router bugs, and requires a “physically proximate attacker” to insert a specially crafted device in order to read or write system memory. Because it needs hands-on physical access rather than remote exploitation, it’s a narrower risk than the router flaws, but owners of affected boards should still grab the fix: BIOS version 1502 for the WS Z390 Pro and 2203 for the other twelve boards.

What router owners should do now

  • Check your router’s current firmware against the affected series listed above and install the update if one is available.
  • Only import VPN client configuration files from trusted, verified sources, Asus’s own recommendation.
  • Set a strong, unique admin password of at least 10 characters mixing uppercase letters, numbers, and symbols.
  • Avoid running scripts, tools, or commands from untrusted sources on any device connected to your network, since social engineering is one way attackers could trick administrators into trouble.
  • If your router is end of life and won’t get a patch, tighten your login and Wi-Fi passwords as a partial mitigation.

The bottom line

Asus has already released firmware fixes for both bugs. If you run an Asus router and use it as a VPN client, or if you’ve left an older device running without updates, this is a good moment to check your firmware version and apply the patch rather than wait. For everyone else, it’s a reminder that router security hinges as much on good password hygiene and cautious file handling as it does on the hardware itself.

Source: Tom's Hardware

The weekly byte

The week's tech news and the best deals, in one email every Friday.

We'll email you a link to confirm. One email a week, unsubscribe anytime.

GigaGuideTech logo
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.