CVE-2026-13313 PUBLISHED

Assigner: ASUS
Reserved: 25.06.2026 Published: 01.10.2026 Updated: 01.10.2026

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 8.9

Product Status

Vendor ASUS
Product Router
Versions Default: unaffected
  • Version 3.0.0.4_386 series is affected
  • Version 3.0.0.4_388 series is affected
  • Version 3.0.0.6_102 series is affected

References

Problem Types

  • CWE-489: Active Debug Code CWE