Impact
The ASUS Router Android App contains an Improper Export of Android Application Components flaw that permits a third‑party application on the same device to issue a crafted Intent, which forces the router app to open an arbitrary URL chosen by the attacker. This weakness, identified as CWE‑926, gives the attacker control over the web view or network traffic initiated by the router app, potentially enabling phishing, credential theft, or delivery of malicious payloads to the device.
Affected Systems
All releases of the ASUS Router Android App that predate the security update detailed in the ASUS advisory are affected. Any device running an unpatched build of the app is vulnerable, regardless of the router model or device manufacturer, as long as the app is installed on an Android platform that allows third‑party intent handling.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires a malicious third‑party app with the ability to send Intents to the ASUS Router App, which typically means an attacker must persuade a user to install such an application. If triggered, the attacker can redirect the router app to any arbitrary URL, potentially compromising user trust and delivering malware. Although exploitation remains unlikely, the possibility of phishing and other user‑agent‑based attacks warrants timely remediation.
OpenCVE Enrichment