Новости компьютерной безопасности:

  Latest News

ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution

С сайта: Vulnerability(cybersecuritynews.com)

ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution

Author: Abinaya

ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices.

The flaw, tracked as CVE-2026-13385, impacts multiple ASUS router firmware branches, including the widely deployed 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series.

According to the ASUS Product Security Advisory, the vulnerability stems from improper input validation within router management components, enabling unauthenticated remote command execution under specific conditions.

Successful exploitation could allow threat actors to gain control over vulnerable routers, potentially leading to network compromise, traffic interception, or deployment of malware such as botnets and ransomware loaders.

The issue is particularly concerning due to the widespread use of ASUS routers in both home and small enterprise environments, where exposed administrative interfaces or misconfigured remote management settings could increase the attack surface.

In real-world scenarios, attackers often scan the internet for exposed routers and chain such vulnerabilities with credential abuse or misconfigurations to gain persistent access.

ASUS Patches Router Vulnerability
ASUS confirmed that firmware updates have been released to remediate the flaw and urged users to upgrade to the latest available versions immediately.

The company emphasized that maintaining up-to-date firmware is critical to preventing exploitation, especially for network edge devices that act as the first line of defense.

The advisory also highlights ASUS’s adherence to Coordinated Vulnerability Disclosure practices and its participation in global security frameworks such as ISO 29147 and ISO 30111.

As a CVE Numbering Authority and member of the Forum of Incident Response and Security Teams, ASUS coordinates with researchers and partners to ensure timely identification and mitigation of security issues.

Security researchers note that router vulnerabilities like CVE-2026-13385 are frequently targeted in large-scale exploitation campaigns.

For example, botnet operators have historically leveraged similar remote code execution flaws to recruit devices into distributed denial-of-service networks or to establish covert proxy infrastructure.

In addition to patching, users are advised to turn off remote administration features unless necessary, enforce strong administrative credentials, and restrict access to management interfaces through trusted IP ranges. Network monitoring for unusual outbound traffic or configuration changes can also help detect potential compromise.

ASUS reiterated that it welcomes responsible vulnerability reports from the security community and maintains a structured disclosure and remediation process through its Product Security Incident Response Team. The company aims to acknowledge reports within three business days and provide ongoing updates throughout the remediation lifecycle.

The release of patches for CVE-2026-13385 follows a series of recent ASUS security updates addressing multiple vulnerabilities across its software ecosystem, reflecting the increasing scrutiny on network infrastructure security as attackers continue to target edge devices.

Organizations and individual users relying on ASUS routers are strongly encouraged to review the official advisory and apply the latest firmware updates immediately to mitigate the risk of exploitation.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment



#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news

Оригинальная версия на сайте: ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.