SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-13385

CRITICAL · CVSS 9.5 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Certain ASUS router models are vulnerable due to improper validation of integrity check values and certificate validation, enabling a remote man-in-the-middle attacker to spoof a server and execute arbitrary commands on the router. This flaw poses a significant security risk, as it could lead to unauthorized access and control over the network. Organizations using affected ASUS routers should prioritize applying the firmware security update to mitigate potential exploitation.

CVE
CVE-2026-13385
Severity
CRITICAL
CVSS
9.5
EPSS
0.14%

Original NVD Description

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the '  Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.