Skip to content
THREATWIRE

CVE

CriticalNo PoC

CVE-2026-14911

ASUS router XSS via crafted URL against authenticated session

ASUS says improper input neutralization (CWE-79) in router modules lets a remote attacker read DOM data, change settings, or cause DoS when an authenticated user opens a crafted URL. CVSS 4.0 9.3. Affects 3.0.0.6.102 series. Not in CISA KEV. No public PoC confirmed.

CVSS
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H
Class
XSS
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
ASUS
Products
ASUS Router (firmware)
Affected
3.0.0.6.102 series, per the ASUS CVE record. Exact model lists and fixed builds are in the Security Update for ASUS Router Firmware section on the ASUS Security Advisory.
Fixed
Latest model firmware from ASUS support / the Security Update for ASUS Router Firmware section on https://www.asus.com/security-advisory/. The CVE text does not publish a single global fixed build number.
Published
7 Oct 2026
Updated
7 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-14911 is a cross-site scripting flaw in ASUS router modules, assigned by ASUS. The CVE description states that improper neutralization of input during web page generation (CWE-79) allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL. ASUS scores CVSS 4.0 9.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H. The privileges-required metric is none because the attacker need not already hold a router login; exploitation still depends on an authenticated victim interacting with the crafted URL (UI:P), so this is not a pre-authentication unauthenticated RCE path.

Affected firmware is the 3.0.0.6.102 series per the CVE affected field. Remediation is the Security Update for ASUS Router Firmware section on the ASUS Security Advisory; the CVE text does not list a single fixed build for every model. NVD published the record on 7 October 2026. GitHub advisory GHSA-hxj2-954q-rw24 mirrors critical severity. CISA has not listed the CVE in KEV. No public proof-of-concept repository was confirmed at drafting time.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-14911