CVE-2026-16528
Received Received - Intake

Insertion of Sensitive Information into Log File in ASUS Router Firmware

Vulnerability report for CVE-2026-16528, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: ASUS

Description

Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ASUS Router 3.0.0.4.386 series
ASUS Router 3.0.0.4.388 series
ASUS Router 3.0.0.6.102 series

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in certain ASUS router models where sensitive DDNS credentials are logged in plaintext. A remote authenticated attacker could access these logs and retrieve the credentials, potentially allowing them to modify DNS settings.

Detection Guidance

Check system logs for ASUS router firmware versions listed in the advisory. Look for unauthorized access attempts or unusual DDNS credential entries in logs. Review network traffic for suspicious DNS query patterns from affected routers.

Impact Analysis

An attacker could use the exposed credentials to alter DNS settings, redirecting your network traffic to malicious servers. This could lead to phishing attacks, data interception, or unauthorized access to your network.

Compliance Impact

This vulnerability may violate data protection requirements under GDPR and HIPAA by exposing sensitive credentials in logs. Organizations could face compliance penalties for failing to protect such information.

Mitigation Strategies

Update ASUS router firmware to the latest version provided in the security advisory. Disable remote access to router administration if not required. Rotate DDNS credentials and monitor logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16528. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart