ASUSCVE-2026-13385
ASUS Router: improper certificate validation
Critical9.5CVE-2026-13385 · Published Jul 15, 2026 · updated Jul 29, 2026
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Router Product | <= 3.0.0.4_386 series | No fix yet |
| <= 3.0.0.4_388 series | No fix yet | |
| <= 3.0.0.6_102 series | No fix yet |
Details and references
More ASUS advisories
All ASUS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 15 | ASUS GameSDK: information disclosure | High7.2 | No fix yet |
| Jul 15 | ASUS Aura Wallpaper Service: local user could perform file operations | High8.5 | No fix yet |
| Jul 15 | ASUS Business Manager: untrusted pointer dereference | High8.4 | No fix yet |
| Jul 15 | ASUS Business Manager: out-of-bounds read | Medium5.6 | No fix yet |
| Jul 15 | ASUS Business Manager: information disclosure | High8.2 | No fix yet |
| Jul 15 | ASUS Router: SQL injection | Medium5.9 | No fix yet |