CVE-2026-14157
Received Received - Intake

Use of Externally Controlled Format String in ASUS Router Web Management

Vulnerability report for CVE-2026-14157, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: ASUS

Description

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus router *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-134 The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in ASUS Router modules where an externally controlled format string can be exploited. A remote authenticated user can execute arbitrary commands by uploading a specially crafted file through the web management interface.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized file uploads or suspicious command execution on ASUS routers. Monitor web management interface logs for unexpected file uploads. Inspect system processes for unusual activity. Use network traffic analysis to detect anomalous outbound connections from the router.

Impact Analysis

An attacker could gain control over your ASUS router, allowing them to execute malicious commands. This could lead to unauthorized access, data theft, or disruption of network services.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations may face compliance violations and legal consequences.

Mitigation Strategies

Immediately update ASUS router firmware to the latest version to patch the vulnerability. Disable remote access to the web management interface if not required. Restrict user permissions to prevent unauthorized file uploads. Monitor network traffic for unusual activity or command execution attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14157. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart