Description
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server.
Refer to the ' 
Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.
Published: 2026-07-15
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from improper validation of both an integrity check value and the server certificate in certain ASUS router firmware versions. A remote attacker positioned as a man–in–the–middle can supply a forged server that the router will accept, leading the device to download and execute arbitrary commands. This flaw equates to a classic remote code execution scenario, enabling full control over the compromised router.

Affected Systems

ASUS routers running firmware 3.0.0.4 for the 386 and 388 series, and firmware 3.0.0.6 for the 102 series are affected. Only the listed model and firmware combinations are known to be vulnerable; other models or versions are not mentioned within the advisory.

Risk and Exploitability

The CVSS score of 9.5 indicates critical severity, while the EPSS score of less than 1% reflects a low exploitation probability at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. An attacker must establish a MITM position to intercept the router’s firmware update traffic, then present a spoofed server that passes the flawed integrity and certificate checks, thereby triggering code execution on the device.

Generated by OpenCVE AI on August 1, 2026 at 09:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the firmware update released by ASUS as stated in the security advisory; if no patch is available for your router model, postpone use of the device until a correction is issued.
  • If an immediate firmware upgrade is not feasible, disable the router’s remote firmware update capability or block the ports used for firmware distribution (e.g., 80/443) through the device’s firewall or an upstream appliance.
  • After applying a patch or disabling the vulnerable feature, monitor traffic to the router for abnormal firmware requests and verify that all future firmware updates are signed by a trusted source.

Generated by OpenCVE AI on August 1, 2026 at 09:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 01 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Routers Vulnerable to Remote Code Execution via Spoofed Server

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Routers Vulnerable to Remote Code Execution via Spoofed Server

Sun, 26 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Spoofed Server Enables Remote Code Execution on ASUS Routers

Wed, 22 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Spoofed Server Enables Remote Code Execution on ASUS Routers

Fri, 17 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Improper Integrity and Certificate Validation Allows Remote Code Execution via Spoofed Server on ASUS Routers

Thu, 16 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Improper Integrity and Certificate Validation Allows Remote Code Execution via Spoofed Server on ASUS Routers

Wed, 15 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the '  Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus router
Weaknesses CWE-295
CWE-354
CPEs cpe:2.3:a:asus:router:3.0.0.4_386_series:*:*:*:*:*:*:*
cpe:2.3:a:asus:router:3.0.0.4_388_series:*:*:*:*:*:*:*
cpe:2.3:a:asus:router:3.0.0.6_102_series:*:*:*:*:*:*:*
Vendors & Products Asus
Asus router
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-29T19:26:45.155Z

Reserved: 2026-06-26T03:42:59.077Z

Link: CVE-2026-13385

cve-icon Vulnrichment

Updated: 2026-07-15T14:22:55.537Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses
  • CWE-295

    Improper Certificate Validation

  • CWE-354

    Improper Validation of Integrity Check Value