ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
ASUS has released critical security updates to address CVE-2026-13385, a vulnerability allowing unauthenticated remote command execution on multiple router firmware versions.

ASUS has issued urgent security patches to fix a critical vulnerability, identified as CVE-2026-13385, that permits unauthenticated remote attackers to execute arbitrary commands on affected devices. This flaw impacts several widely used ASUS router firmware versions, including the 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. The vulnerability arises from inadequate input validation within the router's management interfaces, creating a pathway for attackers to gain control.
Successful exploitation of CVE-2026-13385 could grant threat actors significant access to a user's network. Potential consequences include complete network compromise, the interception of sensitive traffic, or the deployment of malicious software such as botnets or ransomware loaders. The risk is amplified by the common use of ASUS routers in both home and small business environments, where exposed management interfaces or misconfigured remote access settings can broaden the attack surface.
Attackers frequently scan the internet for internet-facing devices with known vulnerabilities, and flaws like this can be chained with other exploits or credential abuse to establish persistent access. ASUS has confirmed that firmware updates are now available to address this issue and strongly advises all users to update their router firmware to the latest version as soon as possible. Maintaining up-to-date firmware is crucial for safeguarding network edge devices, which serve as the primary defense against external threats.
The company highlighted its commitment to coordinated vulnerability disclosure and adherence to international security standards like ISO 29147 and ISO 30111. As a CVE Numbering Authority and a member of FIRST, ASUS collaborates with security researchers to ensure timely identification and mitigation of security risks.
Security experts emphasize that router vulnerabilities are prime targets for large-scale exploitation campaigns. Historically, similar remote code execution flaws have been leveraged by botnet operators to recruit devices for distributed denial-of-service attacks or to create covert proxy networks. Beyond applying the firmware update, users are recommended to disable remote administration features if they are not actively used, enforce strong, unique passwords for administrative accounts, and restrict access to management interfaces to trusted IP addresses.
ASUS also recommends implementing network monitoring to detect unusual outbound traffic patterns or unexpected configuration changes, which could indicate a compromise. The company encourages responsible disclosure of vulnerabilities from the security community and maintains a structured process for reporting and remediation through its Product Security Incident Response Team.
This patch release follows a series of recent security updates from ASUS, underscoring the ongoing focus on securing network infrastructure against evolving threats targeting edge devices. Users and organizations relying on ASUS routers are urged to consult the official ASUS Product Security Advisory and apply the necessary firmware updates promptly to protect their networks from potential exploitation of CVE-2026-13385.