Description
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL.
Refer to the '
Security Update for ASUS Router Android App ' section on the ASUS Security Advisory for more information.
Published: 2026-07-03
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ASUS Router Android App contains an Improper Export of Android Application Components flaw that permits a third‑party application on the same device to issue a crafted Intent, which forces the router app to open an arbitrary URL chosen by the attacker. This weakness, identified as CWE‑926, gives the attacker control over the web view or network traffic initiated by the router app, potentially enabling phishing, credential theft, or delivery of malicious payloads to the device.

Affected Systems

All releases of the ASUS Router Android App that predate the security update detailed in the ASUS advisory are affected. Any device running an unpatched build of the app is vulnerable, regardless of the router model or device manufacturer, as long as the app is installed on an Android platform that allows third‑party intent handling.

Risk and Exploitability

The CVSS score of 6 indicates moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires a malicious third‑party app with the ability to send Intents to the ASUS Router App, which typically means an attacker must persuade a user to install such an application. If triggered, the attacker can redirect the router app to any arbitrary URL, potentially compromising user trust and delivering malware. Although exploitation remains unlikely, the possibility of phishing and other user‑agent‑based attacks warrants timely remediation.

Generated by OpenCVE AI on July 22, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest ASUS Router Android App update from the official ASUS website, as described in the Security Advisory.
  • Remove or disable any installed third‑party applications that grant broad intent‑handling permissions or are known to misuse intents, thereby preventing them from targeting the router app.
  • Turn on Android’s restriction for installing apps from unknown sources and keep the operating system and all other applications updated to reduce the overall attack surface.

Generated by OpenCVE AI on July 22, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Application Components Enables Unauthorized URL Navigation in ASUS Router App

Thu, 16 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Application Components Allows Malicious URL Launch in ASUS Router App

Tue, 14 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Application Components Allows Malicious URL Launch in ASUS Router App

Mon, 13 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Enables Arbitrary URL Invocation via Intent

Sun, 12 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Enables Arbitrary URL Invocation via Intent

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unrestricted Intent Handling in ASUS Router Android App Enables Arbitrary URL Invocation

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unrestricted Intent Handling in ASUS Router Android App Enables Arbitrary URL Invocation

Thu, 09 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Enables Arbitrary URL Invocation by Third‑Party Apps

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Enables Arbitrary URL Invocation by Third‑Party Apps

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Improper Export Enables Arbitrary URL Invocation via Intent

Tue, 07 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Improper Export Enables Arbitrary URL Invocation via Intent

Mon, 06 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Application Components Allows Unauthorized URL Navigation in ASUS Router App

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Application Components Allows Unauthorized URL Navigation in ASUS Router App

Sun, 05 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Enabling Arbitrary URL Invocation

Sat, 04 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Enabling Arbitrary URL Invocation

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Allows Third‑Party Apps to Open Arbitrary URLs in ASUS Router App

Fri, 03 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Export of Android Components Allows Third‑Party Apps to Open Arbitrary URLs in ASUS Router App

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Description An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus router App
Weaknesses CWE-926
CPEs cpe:2.3:a:asus:router_app:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus router App
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-06T15:42:50.120Z

Reserved: 2026-06-23T05:33:05.433Z

Link: CVE-2026-12960

cve-icon Vulnrichment

Updated: 2026-07-06T15:42:45.491Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-926

    Improper Export of Android Application Components