CVE-2026-19396
ASUS RT-BE57 IFTTT pairing token from predictable PRNG seed
ASUS says a predictable PRNG seed (CWE-337) in IFTTT pairing-token generation on the RT-BE57 lets an unauthenticated nearby attacker derive the token from an administrator-initiated pairing session and read or modify settings. CVSS 4.0 7.7. Affects 3.0.0.6_102 series. Not in CISA KEV. No public PoC confirmed.
- CVSS
- 7.7
- Vector
- CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- Class
- Auth bypass
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- ASUS
- Products
- ASUS RT-BE57 Router (firmware)
- Affected
- 3.0.0.6_102 series, per the ASUS CVE record. The description specifically names the RT-BE57 IFTTT pairing flow.
- Fixed
- Latest model firmware from ASUS support / the Security Update for ASUS Router Firmware section on https://www.asus.com/security-advisory/. The CVE text does not publish a single global fixed build number.
- CWE
- CWE-337
- Published
- 7 Oct 2026
- Updated
- 7 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-19396 is a predictable-seed weakness in IFTTT pairing-token generation on the ASUS RT-BE57 router, assigned by ASUS. The CVE description states that a predictable seed in the pseudo-random number generator (CWE-337) allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via values observed from an administrator-initiated IFTTT pairing session. ASUS scores CVSS 4.0 7.7 with vector CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Privileges required are none, but attack complexity is high, attack requirements are present, and the vector is adjacent—so this is not a trivial unauthenticated internet attack and depends on observing an admin-initiated pairing session from the local segment.
Affected firmware is recorded as the 3.0.0.6_102 series, with the narrative scoped to the RT-BE57 IFTTT pairing path. Remediation is the Security Update for ASUS Router Firmware section on the ASUS Security Advisory. NVD published the record on 7 October 2026. GitHub advisory GHSA-fcpg-rqrm-22xm mirrors high severity. CISA has not listed the CVE in KEV. No public proof-of-concept repository was confirmed at drafting time.