ASUSCVE-2026-13313
ASUS Router: debug code left active
High8.9CVE-2026-13313 · Published Oct 1, 2026 · updated Oct 2, 2026
An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Router Product | <= 3.0.0.4_386 series | No fix yet |
| <= 3.0.0.4_388 series | No fix yet | |
| <= 3.0.0.6_102 series | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-489
More ASUS advisories
All ASUS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Improper initialization in an ASUS certain motherboard | High7.0 | No fix yet |
| Oct 1 | ASUS Router: remote code execution | Critical9.4 | No fix yet |
| Sep 8 | ASUS Armoury Crate: local user could modify hardware configuration settings | Medium5.8 | No fix yet |
| Sep 8 | ASUS Armoury Crate: information disclosure | Medium5.7 | No fix yet |
| Sep 8 | ASUS Control Center Express Agent: missing authentication | High7.7 | No fix yet |
| Sep 8 | ASUS Armoury Crate: denial of service | Medium5.7 | No fix yet |