Description
An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router.
Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.asus.com/security-advisory |
|
History
Thu, 01 Oct 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information. | |
| First Time appeared |
Asus
Asus router |
|
| Weaknesses | CWE-489 | |
| CPEs | cpe:2.3:a:asus:router:3.0.0.4_386_series:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.4_388_series:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.6_102_series:*:*:*:*:*:*:* |
|
| Vendors & Products |
Asus
Asus router |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ASUS
Published:
Updated: 2026-10-01T02:00:57.434Z
Reserved: 2026-06-25T06:14:34.338Z
Link: CVE-2026-13313
No data.
Status : Received
Published: 2026-10-01T02:16:53.817
Modified: 2026-10-01T02:16:53.817
Link: CVE-2026-13313
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-489
Active Debug Code