CVE-2026-13313
Received Received - Intake

Active Debug Code Enables Root Command Execution in ASUS Router Firmware

Vulnerability report for CVE-2026-13313, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: ASUS

Description

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router FirmwareΒ ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus router *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-489 The product is released with debugging code still enabled or active.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a remote authenticated attacker to bypass security controls in certain ASUS routers by sending a specially crafted HTTP request. This enables the Telnet service, which can then be used to execute arbitrary commands with root privileges on the router. The attacker could potentially gain full control over the device and any connected systems.

Detection Guidance

To detect this vulnerability, check if Telnet is enabled on ASUS routers via HTTP requests or admin interfaces. Monitor for unauthorized changes to router settings or unexpected command execution. Inspect network traffic for suspicious connections to port 23 (Telnet).

Impact Analysis

If you use an affected ASUS router, an attacker could exploit this to gain root access, allowing them to monitor network traffic, steal data, install malware, or use your router as a pivot point to attack other devices on your network. This could lead to loss of privacy, financial damage, or further compromise of connected systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations may face regulatory fines, legal liabilities, and reputational damage if this flaw is exploited to compromise personal or health data.

Mitigation Strategies

Update ASUS router firmware to the latest version as recommended in the ASUS Security Advisory to address the Active Debug Code vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13313. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart