Skip to content
ASUSCVE-2026-13313

ASUS Router: debug code left active

High8.9CVE-2026-13313 · Published Oct 1, 2026 · updated Oct 2, 2026

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.

ASUS advisory

Affected versions

PackageAffectedFixed in
Router
Product
<= 3.0.0.4_386 seriesNo fix yet
<= 3.0.0.4_388 seriesNo fix yet
<= 3.0.0.6_102 seriesNo fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-489

More ASUS advisories

All ASUS
Advisory
Improper initialization in an ASUS certain motherboard
High7.0Oct 1
ASUS Router: remote code execution
Critical9.4Oct 1
ASUS Armoury Crate: local user could modify hardware configuration settings
Medium5.8Sep 8
ASUS Armoury Crate: information disclosure
Medium5.7Sep 8
ASUS Control Center Express Agent: missing authentication
High7.7Sep 8
ASUS Armoury Crate: denial of service
Medium5.7Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.