OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-14157

CRITICAL · CVSS 9.4 EPSS 0.76%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

ASUS Router modules are vulnerable to a critical issue that allows remote authenticated users to execute arbitrary commands due to the use of an externally controlled format string. This vulnerability can be exploited through a crafted file uploaded via the web management interface, potentially leading to unauthorized access and control over the device. Organizations using affected ASUS Router products should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-14157
Severity
CRITICAL
CVSS
9.4
EPSS
0.76%

Original NVD Description

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.