ASUS router firmware security update covers four CVEs
ASUS published four router firmware CVEs on 7 October 2026: CVE-2026-14911 XSS (CVSS 4.0 9.3), CVE-2026-19386 authenticated adjacent config-upload RCE (9.3), CVE-2026-16528 DDNS log disclosure (8.4), and CVE-2026-19396 IFTTT PRNG token (7.7). Update firmware. Not in CISA KEV. No public PoC confirmed.
Published 7 Oct 2026
What happened
On 7 October 2026 ASUS published four CVE records that all point to the Security Update for ASUS Router Firmware section on the ASUS Security Advisory. The critical pair is CVE-2026-14911 (cross-site scripting, CVSS 4.0 9.3) and CVE-2026-19386 (stack-based buffer overflow to code execution, CVSS 4.0 9.3). Two additional high-severity issues in the same wave are CVE-2026-16528 (DDNS credentials in the system log, CVSS 4.0 8.4) and CVE-2026-19396 (predictable IFTTT pairing-token PRNG on the RT-BE57 path, CVSS 4.0 7.7). This ThreatWire batch records those four CVEs only. Earlier October ASUS router issues such as the VPN format-string and active-debug Telnet CVEs are separate advisories.
Who is affected
Owners of ASUS routers on the 3.0.0.6.102 / 3.0.0.6_102 firmware series are in scope for CVE-2026-14911, CVE-2026-19386, and CVE-2026-19396. CVE-2026-16528 also lists the older 3.0.0.4.386 and 3.0.0.4.388 series. Exact model coverage and download links are model-specific on ASUS support; the CVE texts do not publish one global fixed build. Auth requirements differ sharply: the XSS needs an authenticated victim to open a crafted URL; the overflow and DDNS log issues require high-privilege authentication and adjacent access; the IFTTT PRNG issue is unauthenticated but adjacent, high complexity, and depends on observing an administrator-initiated pairing session.
What is confirmed
ASUS’s CVE wording confirms CWE-79 XSS impact (DOM read, settings change, DoS) for CVE-2026-14911; CWE-121 stack overflow via oversized configuration upload for CVE-2026-19386; CWE-532 DDNS credential exposure in logs for CVE-2026-16528; and CWE-337 predictable PRNG seed for IFTTT pairing on the RT-BE57 narrative for CVE-2026-19396. Vendor CVSS 4.0 scores are 9.3, 9.3, 8.4, and 7.7 respectively. GitHub advisories GHSA-hxj2-954q-rw24, GHSA-rx2g-2998-5867, GHSA-jh3c-v2fg-3q6f, and GHSA-fcpg-rqrm-22xm track the four ids. None of the four is in CISA KEV.
What is not confirmed
Neither CVE text claims exploitation in the wild. No public proof-of-concept repositories matching these CVE ids were found at drafting time, so ThreatWire leaves availability at none and does not attach a PoC URL. Posts that frame CVE-2026-19386 as unauthenticated internet RCE contradict the CVSS adjacent + high-privilege requirements. Posts that treat CVE-2026-14911 as pre-auth without a logged-in victim ignore the authenticated-user visit condition in ASUS’s description.
What to do
Install the latest firmware for each affected model from ASUS support, following the Security Update for ASUS Router Firmware guidance on the ASUS Security Advisory. Until then, keep WAN remote management disabled, use a strong unique administrator password, avoid opening untrusted management URLs while logged in, and do not upload untrusted configuration files. After upgrading, change the admin password and review DDNS credentials if logs may have been exposed.
Sources: ASUS Security Advisory, NVD and CVE.org for CVE-2026-14911, CVE-2026-19386, CVE-2026-16528, and CVE-2026-19396, and the four matching GitHub Security Advisories.