Skip to content
THREATWIRE

CVE

CriticalNo PoC

CVE-2026-19386

ASUS router stack overflow via crafted config upload

ASUS says a stack-based buffer overflow (CWE-121) lets an authenticated nearby user execute arbitrary code by uploading a crafted configuration file that exceeds the expected buffer. CVSS 4.0 9.3. Affects 3.0.0.6.102 series. Not in CISA KEV. No public PoC confirmed.

CVSS
9.3
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Class
RCE
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
ASUS
Products
ASUS Router (firmware)
Affected
3.0.0.6.102 series, per the ASUS CVE record. Exact model lists and fixed builds are in the Security Update for ASUS Router Firmware section on the ASUS Security Advisory.
Fixed
Latest model firmware from ASUS support / the Security Update for ASUS Router Firmware section on https://www.asus.com/security-advisory/. The CVE text does not publish a single global fixed build number.
Published
7 Oct 2026
Updated
7 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-19386 is a stack-based buffer overflow in ASUS router modules, assigned by ASUS. The CVE description states that an authenticated nearby user can execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size (CWE-121). ASUS scores CVSS 4.0 9.3 with vector CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. Attack vector adjacent and privileges high mean this is not a pre-authentication internet-facing overflow: the attacker needs high-privilege authentication and adjacency (typically the same LAN or Wi-Fi segment as the management interface).

Affected firmware is the 3.0.0.6.102 series. Remediation is the Security Update for ASUS Router Firmware section on the ASUS Security Advisory; the CVE text does not list a single fixed build for every model. NVD published the record on 7 October 2026. GitHub advisory GHSA-rx2g-2998-5867 mirrors critical severity. CISA has not listed the CVE in KEV. No public proof-of-concept repository was confirmed at drafting time.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-19386