Skip to content
THREATWIRE

CVE

HighNo PoC

CVE-2026-19396

ASUS RT-BE57 IFTTT pairing token from predictable PRNG seed

ASUS says a predictable PRNG seed (CWE-337) in IFTTT pairing-token generation on the RT-BE57 lets an unauthenticated nearby attacker derive the token from an administrator-initiated pairing session and read or modify settings. CVSS 4.0 7.7. Affects 3.0.0.6_102 series. Not in CISA KEV. No public PoC confirmed.

CVSS
7.7
Vector
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Class
Auth bypass
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
ASUS
Products
ASUS RT-BE57 Router (firmware)
Affected
3.0.0.6_102 series, per the ASUS CVE record. The description specifically names the RT-BE57 IFTTT pairing flow.
Fixed
Latest model firmware from ASUS support / the Security Update for ASUS Router Firmware section on https://www.asus.com/security-advisory/. The CVE text does not publish a single global fixed build number.
Published
7 Oct 2026
Updated
7 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-19396 is a predictable-seed weakness in IFTTT pairing-token generation on the ASUS RT-BE57 router, assigned by ASUS. The CVE description states that a predictable seed in the pseudo-random number generator (CWE-337) allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via values observed from an administrator-initiated IFTTT pairing session. ASUS scores CVSS 4.0 7.7 with vector CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Privileges required are none, but attack complexity is high, attack requirements are present, and the vector is adjacent—so this is not a trivial unauthenticated internet attack and depends on observing an admin-initiated pairing session from the local segment.

Affected firmware is recorded as the 3.0.0.6_102 series, with the narrative scoped to the RT-BE57 IFTTT pairing path. Remediation is the Security Update for ASUS Router Firmware section on the ASUS Security Advisory. NVD published the record on 7 October 2026. GitHub advisory GHSA-fcpg-rqrm-22xm mirrors high severity. CISA has not listed the CVE in KEV. No public proof-of-concept repository was confirmed at drafting time.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-19396