Asus Patched Critical Router and Motherboard Security Flaws

The updates address remote command execution and memory access bugs in routers and motherboards.

Updated on Oct. 3, 2026 in Cybersecurity

Isometric editorial illustration of a complex circuit board and heat-sink architecture, representing secure computer hardware.
Asus released critical firmware updates to patch high-severity vulnerabilities in its router and motherboard lineups, preventing potential remote command execution. AI Illustration. Upload story photo >

Live Poll

Do you feel confident in your ability to keep your home's connected devices secure?

Asus has released firmware updates to mitigate high-severity vulnerabilities affecting its routers and motherboard models. These flaws, which include remote command execution and unauthorized memory access, have been assigned identifiers CVE-2026-14157 and CVE-2026-13313.

Why it matters

Securing home and enterprise network infrastructure is critical given the history of large-scale campaigns like AyySSHush, which compromised thousands of routers. These updates address underlying architecture issues that could allow attackers to gain full system control.

The router vulnerabilities impact firmware series 3.0.0.6_102, with the Telnet bug also affecting series 3.0.0.4_386 and 3.0.0.4_388. A separate motherboard memory vulnerability led to BIOS version 1502 for the WS Z390 Pro and 2203 for 12 other models.

The players

Asus

A hardware manufacturer producing motherboards, networking gear, and consumer electronics.

VulnCheck

A security research organization that tracks and discloses software vulnerabilities.

The details

The VPN configuration vulnerability occurs when the system processes crafted text within uploaded configuration files as formatting instructions, allowing arbitrary command execution. The Telnet flaw utilizes leftover debug code that bypasses standard authentication to grant root-level privileges. Additionally, a memory vulnerability allows physical attackers to read or write directly to system memory on specific motherboard units.

Timeline

  1. 2024: VulnCheck disclosed the previous router bug CVE-2024-0401.

  2. October 3, 2026: Asus published current firmware and BIOS patches.

The Tech Race

This effort to patch firmware mirrors the ongoing industry challenge of maintaining secure device ecosystems against mass exploitation. It follows the precedent set by the AyySSHush campaign, which affected 9,000 devices and signaled a shift toward more rigorous patching requirements.

Users should update their Asus routers to the latest firmware versions and their motherboards to the specified BIOS releases to close these security gaps. Additionally, administrators should implement a minimum password length of 10 characters to harden their network devices against unauthorized access.

The takeaway

The security of network hardware remains a primary vector for potential system compromise, necessitating regular firmware hygiene. Watch for future announcements regarding end-of-life device support, as these legacy units will not receive the updates required to mitigate new CVE disclosures.

Further reading

For more information on securing infrastructure, visit Cybersecurity.

Source note: This article includes information reported by Tom's Hardware.

Live Poll

Do you feel confident in your ability to keep your home's connected devices secure?