Tendvane

← All articles

NetworkOctober 1, 2026

ASUS says the danger is the VPN file you import, not the one you connect to

Ever downloaded a VPN configuration file from a forum post or a cheap provider's website? ASUS would rather you did not feed it to your router.

The company published fixes on 1 October for two flaws in Asuswrt, the software inside its home routers. The serious one, CVE-2026-14157, scores 9.4. It is a format string bug in the web management interface, and it fires when the router is given a crafted VPN client configuration file. Import that file and the router runs whatever commands were hidden inside it. The second, CVE-2026-13313 at 8.9, is leftover debug code: oddly shaped HTTP requests slip past the normal checks and switch on Telnet, which hands over root. Both need the attacker to be logged in first, which makes a router still using the password printed on its sticker the real weak point.

The affected firmware spans the 3.0.0.4_386, 3.0.0.4_388 and 3.0.0.6_102 branches, covering a lot of ASUS hardware sold over the past several years. Nobody has reported either flaw being used, and no exploit code is public. ASUS also pushed BIOS updates for 13 older Z390 motherboards, including the PRIME Z390-A and the ROG MAXIMUS XI and STRIX Z390 boards, for CVE-2026-93495. That one needs somebody to physically plug a device into the machine, so it matters most for PCs other people can walk up to.

Updating an ASUS router means a browser, router.asus.com, and the firmware upgrade page. Change the admin password while you are in there if it is still the one that came in the box. Tendvane's network scan lists every device on your home network and what each one is, which is the quickest way to confirm what router you actually own before you go hunting for the right firmware file.

Sources

Download Tendvane