CVE-2026-14911
ASUS router XSS via crafted URL against authenticated session
ASUS says improper input neutralization (CWE-79) in router modules lets a remote attacker read DOM data, change settings, or cause DoS when an authenticated user opens a crafted URL. CVSS 4.0 9.3. Affects 3.0.0.6.102 series. Not in CISA KEV. No public PoC confirmed.
- CVSS
- 9.3
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H
- Class
- XSS
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- ASUS
- Products
- ASUS Router (firmware)
- Affected
- 3.0.0.6.102 series, per the ASUS CVE record. Exact model lists and fixed builds are in the Security Update for ASUS Router Firmware section on the ASUS Security Advisory.
- Fixed
- Latest model firmware from ASUS support / the Security Update for ASUS Router Firmware section on https://www.asus.com/security-advisory/. The CVE text does not publish a single global fixed build number.
- CWE
- CWE-79
- Published
- 7 Oct 2026
- Updated
- 7 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-14911 is a cross-site scripting flaw in ASUS router modules, assigned by ASUS. The CVE description states that improper neutralization of input during web page generation (CWE-79) allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL. ASUS scores CVSS 4.0 9.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H. The privileges-required metric is none because the attacker need not already hold a router login; exploitation still depends on an authenticated victim interacting with the crafted URL (UI:P), so this is not a pre-authentication unauthenticated RCE path.
Affected firmware is the 3.0.0.6.102 series per the CVE affected field. Remediation is the Security Update for ASUS Router Firmware section on the ASUS Security Advisory; the CVE text does not list a single fixed build for every model. NVD published the record on 7 October 2026. GitHub advisory GHSA-hxj2-954q-rw24 mirrors critical severity. CISA has not listed the CVE in KEV. No public proof-of-concept repository was confirmed at drafting time.