📣 Send us your press release
Site updates every 15 minutes
Technology

ASUS fixes critical security vulnerability in routers

ASUS released a security update on July 15 to address a critical firmware vulnerability (CVE-2026-13385) in its China-market routers. The flaw allowed remote command execution and received a CVSS score of 9.5.

26 July 2026
ASUS fixes critical security vulnerability in routers
Image is an AI-generated illustration

IT Home reported on July 26 that ASUS issued a security update on July 15 to fix a critical firmware vulnerability, identified as CVE-2026-13385, affecting routers sold in China. The vulnerability, with a CVSS risk score of 9.5, was classified as critical.

The issue stems from improper certificate validation within the UU function of the ASUSWRT firmware (versions ASUSWRT 3.0.0.4_386, 3.0.0.4_388, 3.0.0.6_102 series) used in China-specific (CN SKU) ASUS router models. Attackers could exploit this through a Man-in-the-Middle (MITM) attack, tricking the router into connecting to a spoofed server to download and execute arbitrary commands.

ASUS advises affected users to upgrade to the latest firmware version promptly to resolve the security problem. For older devices that are no longer officially supported and cannot receive firmware updates, users are advised to disable the UU function to mitigate the risk of potential attacks.

The UU function typically refers to ASUS's "UU Accelerator" service, a game network acceleration feature offered in cooperation with NetEase UU. Its primary purpose is to optimize game connections by reducing latency and packet loss.

Original source: ithome.com