Skip to content
THREATWIRE

CVE

HighNo PoC

CVE-2026-16528

ASUS router DDNS credentials exposed in system log

ASUS says sensitive information inserted into the system log (CWE-532) lets a remote authenticated attacker obtain DDNS credentials and potentially modify DNS settings. CVSS 4.0 8.4. Affects 3.0.0.4.386, 3.0.0.4.388, and 3.0.0.6.102 series. Not in CISA KEV. No public PoC confirmed.

CVSS
8.4
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Class
Info disclosure
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
ASUS
Products
ASUS Router (firmware)
Affected
3.0.0.4.386 series, 3.0.0.4.388 series, and 3.0.0.6.102 series, per the ASUS CVE record.
Fixed
Latest model firmware from ASUS support / the Security Update for ASUS Router Firmware section on https://www.asus.com/security-advisory/. The CVE text does not publish a single global fixed build number.
Published
7 Oct 2026
Updated
7 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-16528 is an information-disclosure issue in certain ASUS router models, assigned by ASUS. The CVE description states that insertion of sensitive information into a log file (CWE-532) allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings. ASUS scores CVSS 4.0 8.4 with vector CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N. Privileges required are high and the attack vector is adjacent, so this is not an unauthenticated internet-wide leak.

Affected firmware series are 3.0.0.4.386, 3.0.0.4.388, and 3.0.0.6.102. Remediation is the Security Update for ASUS Router Firmware section on the ASUS Security Advisory. NVD published the record on 7 October 2026. GitHub advisory GHSA-jh3c-v2fg-3q6f mirrors high severity. CISA has not listed the CVE in KEV. No public proof-of-concept repository was confirmed at drafting time.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-16528