Back
Asus patches VPN file and Telnet flaws in routers
SiTech AI Team2 min read

Asus patches VPN file and Telnet flaws in routers

Asus has patched two router vulnerabilities involving crafted VPN client files and active debug code that can enable Telnet. The company also fixed a memory flaw affecting 13 motherboards.

VPN file and Telnet flaws

A crafted VPN client configuration file uploaded through an Asus router's web management interface can allow an adversary to execute arbitrary commands. The issue, CVE-2026-14157, scores 9.4 out of 10 on the Common Vulnerability Scoring System 4.0 scale. Asus has patched the flaw and recommends importing VPN client configuration files only from trusted sources.

A separate vulnerability, CVE-2026-13313, uses debug code left active to bypass security checks and enable Telnet. It may allow commands to run with root privileges, potentially affecting devices connected to the router. The flaw scores 8.9 out of 10. Firmware series 3.0.0.6_102 is affected by both bugs, while the 3.0.0.4_386 and 3.0.0.4_388 series are also affected by the Telnet flaw.

Exposure and recommended action

The VPN issue applies to owners who import a configuration file into an Asus router configured as a VPN client, not to VPN apps on laptops or phones. Crafted text in an imported file can be interpreted as formatting instructions instead of plain data. The web administration import path is a recurring weak point: CVE-2026-14157 uses the same entry point as CVE-2024-0401, which involved a crafted OVPN profile and was disclosed by VulnCheck in 2024.

Asus recommends a strong, unique administrator password with at least 10 characters, including a mix of uppercase letters, numbers and symbols. It also advises against running scripts, tools or commands from untrusted sources on devices within the local network. Affected users should check Asus's support or product pages for firmware updates. Routers that have reached end of life will not receive new firmware, so their owners are advised to use strong, unique login and Wi-Fi passwords.

Fix covers 13 motherboards

Asus also fixed a vulnerability affecting 13 motherboards. A physically proximate attacker could read or write arbitrary system memory by inserting a specially crafted device. The flaw affects many Z390 and C240 motherboards, requires physical access and has a severity score of 7.0 out of 10.

The fix is BIOS version 1502 for the WS Z390 Pro and version 2203 for the other 12 motherboards.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.