CVE-2026-16528
ASUS router DDNS credentials exposed in system log
ASUS says sensitive information inserted into the system log (CWE-532) lets a remote authenticated attacker obtain DDNS credentials and potentially modify DNS settings. CVSS 4.0 8.4. Affects 3.0.0.4.386, 3.0.0.4.388, and 3.0.0.6.102 series. Not in CISA KEV. No public PoC confirmed.
- CVSS
- 8.4
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
- Class
- Info disclosure
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- ASUS
- Products
- ASUS Router (firmware)
- Affected
- 3.0.0.4.386 series, 3.0.0.4.388 series, and 3.0.0.6.102 series, per the ASUS CVE record.
- Fixed
- Latest model firmware from ASUS support / the Security Update for ASUS Router Firmware section on https://www.asus.com/security-advisory/. The CVE text does not publish a single global fixed build number.
- CWE
- CWE-532
- Published
- 7 Oct 2026
- Updated
- 7 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-16528 is an information-disclosure issue in certain ASUS router models, assigned by ASUS. The CVE description states that insertion of sensitive information into a log file (CWE-532) allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings. ASUS scores CVSS 4.0 8.4 with vector CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N. Privileges required are high and the attack vector is adjacent, so this is not an unauthenticated internet-wide leak.
Affected firmware series are 3.0.0.4.386, 3.0.0.4.388, and 3.0.0.6.102. Remediation is the Security Update for ASUS Router Firmware section on the ASUS Security Advisory. NVD published the record on 7 October 2026. GitHub advisory GHSA-jh3c-v2fg-3q6f mirrors high severity. CISA has not listed the CVE in KEV. No public proof-of-concept repository was confirmed at drafting time.