Impact
The vulnerability stems from improper validation of both an integrity check value and the server certificate in certain ASUS router firmware versions. A remote attacker positioned as a man–in–the–middle can supply a forged server that the router will accept, leading the device to download and execute arbitrary commands. This flaw equates to a classic remote code execution scenario, enabling full control over the compromised router.
Affected Systems
ASUS routers running firmware 3.0.0.4 for the 386 and 388 series, and firmware 3.0.0.6 for the 102 series are affected. Only the listed model and firmware combinations are known to be vulnerable; other models or versions are not mentioned within the advisory.
Risk and Exploitability
The CVSS score of 9.5 indicates critical severity, while the EPSS score of less than 1% reflects a low exploitation probability at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. An attacker must establish a MITM position to intercept the router’s firmware update traffic, then present a spoofed server that passes the flawed integrity and certificate checks, thereby triggering code execution on the device.
OpenCVE Enrichment