Threat reportVulnerabilityTL-2026-1617

Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command Execution

criticalPATCHED

Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM (TL-2026-1617) is a critical-severity software vulnerability scored CVSS 9.5, first published 2026-07-22. It has no confirmed attribution, affects ASUS Router (multiple models sharing affected firmware series), references 1 CVE (CVE-2026-13385), maps to 15 MITRE ATT&CK techniques (T1046, T1059, T1090), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
9.5/10Critical
CVEs
1Referenced vulnerabilities
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-1617

Threat ID
TL-2026-1617
Severity
CRITICAL
CVSS
9.5 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
consumer, smallofficehomeoffice, telecoms, criticalinfrastructureedge
Target regions
Global
Detection rules
9
Indicators of compromise
16

How Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM works

CVE-2026-13385 (CVSS 4.0: 9.5, CRITICAL) is an improper integrity-check-value validation and improper certificate validation flaw in certain ASUS router firmware series (3.0.0.4_386, 3.0.0.4_388, 3.0.0.6_102) that allows a network-adjacent man-in-the-middle attacker to spoof a firmware/update server and trick the router into downloading and executing arbitrary commands. ASUS has released patched firmware; no public PoC or confirmed active exploitation has been reported.

CVE-2026-13385 is a critical improper-validation vulnerability affecting certain ASUS router firmware builds in the 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. The root cause is dual: (1) CWE-354 Improper Validation of Integrity Check Value — the router firmware/update or configuration-sync client does not correctly validate a cryptographic integrity check (e.g. checksum/signature) on data received from a remote server, and (2) CWE-295 Improper Certificate Validation — the same client fails to properly validate the TLS certificate presented by that remote server. Combined, these defects mean the router's update/sync mechanism can be tricked into trusting a server that is not the legitimate ASUS/cloud endpoint, provided the attacker can position themselves as a man-in-the-middle (MITM) on the network path between the router and that server — e.g. via ARP/DNS spoofing on the LAN, a rogue access point, a compromised upstream ISP hop, or interception on an untrusted network the router's WAN traverses.

An attacker who achieves this MITM position can stand up a spoofed server that mimics the expected update/response payload. Because the router does not verify server identity (invalid/self-signed/mismatched certificate accepted) and does not verify payload integrity (a manipulated or unsigned blob passes the check), the spoofed server can supply a malicious payload that the router downloads and executes as a command — i.e., the flaw provides a direct path from network-level interception to command execution on the device, with no user interaction and no authentication required (CVSS 4.0 vector: AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — network vector, low complexity, attack requirements present [MITM position needed], no privileges, no user interaction, high impact to confidentiality/integrity/availability of both the vulnerable system and any subsequent system it can reach).

Post-exploitation impact on a compromised SOHO/consumer router is severe given its position as the network's default gateway: full device takeover, persistent implant/backdoor installation, DNS hijacking of every downstream client, further traffic interception (defeating the very trust boundary the router is meant to protect), pivoting to internal LAN hosts, and recruitment into a router/IoT botnet for DDoS or proxy (residential-proxy / anonymization) infrastructure — impact patterns consistent with historical ASUS router compromise campaigns (e.g. the 2025 GreyNoise-documented stealthy ASUS backdoor campaign affecting thousands of devices, which is a separate incident/CVE but illustrates the exploitation ceiling for this device class).

As of this writing there is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation; the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. ASUS has already shipped patched firmware for the affected series and — per its Product Security Incident Response practice, which follows ISO/IEC 29147:2018 (vulnerability disclosure) and ISO/IEC 30111:2019 (vulnerability handling) — strongly advises all affected-model owners to update immediately. Because exploitation requires a MITM position, the primary practical exposure window is for devices whose WAN/administrative traffic traverses untrusted or attacker-influenced network segments before the firmware update is applied.

MITRE ATT&CK techniques used in TL-2026-1617

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Command and Control

T1090 Proxy; T1102 Web Service

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1498 Network Denial of Service; T1565 Data Manipulation

defense-impairment

T1553 Subvert Trust Controls

Persistence

T1554 Compromise Host Software Binary; T1556 Modify Authentication Process

credential-access

T1557 Adversary-in-the-Middle

Credential Access

T1557 Adversary-in-the-Middle

Collection

T1557 Adversary-in-the-Middle

Resource Development

T1584 Compromise Infrastructure

Reconnaissance

T1595 Active Scanning

Affected products and versions in Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM

  • ASUS — Router (multiple models sharing affected firmware series)
    Vulnerable versions: 3.0.0.4_386; 3.0.0.4_388; 3.0.0.6_102
    Fixed in: Patched firmware released by ASUS post-2026-07-15 addressing CVE-2026-13385 (see ASUS Security Advisory for model-specific build numbers)

Remediation for Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM

Patches

  • Apply the ASUS Security Advisory firmware update for CVE-2026-13385 (see ASUS Security Advisory portal, asus.com/security-advisory)

Immediate actions

  • Update all affected ASUS router models to the patched firmware release addressing CVE-2026-13385
  • Avoid connecting the router's WAN interface or administrative sessions to untrusted or public networks where a MITM position is achievable until patched
  • Restrict/disable remote administration and any cloud-sync/auto-update client where feasible while awaiting patch confirmation
  • Verify current firmware version against the affected series (3.0.0.4_386, 3.0.0.4_388, 3.0.0.6_102) via the router admin UI

Workarounds

  • If immediate patching is not possible, disable remote/cloud-based firmware update and configuration-sync features and perform manual, verified firmware installation from the official ASUS support site

Longer-term hardening

  • Enforce certificate pinning / strict TLS validation for all device-to-cloud and firmware-update channels
  • Cryptographically sign and verify update payloads with a robust integrity check independent of TLS trust
  • Deploy network segmentation isolating router management interfaces from general LAN/WAN traffic
  • Monitor router DNS and outbound configuration for unauthorized changes indicative of MITM tampering
  • Maintain an asset inventory of ASUS router models/firmware versions to accelerate future patch rollouts

CVEs associated with Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM

CVE-2026-13385

Weaknesses (CWE) in Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM

CWE-295, CWE-354

Timeline of Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM

  • CVE-2026-13385 identifier reserved by MITRE's CVE Numbering Authority process, roughly three weeks ahead of public disclosure.
  • Threat-intelligence aggregators (OffSeq Threat Radar, TheHackerWire) publish technical summaries of CVE-2026-13385 including CWE mapping and CVSS v4.0 vector.
  • INCIBE-CERT publishes an early-warning advisory for CVE-2026-13385, confirming CVSS 9.5 CRITICAL classification and affected firmware series.
  • CVE-2026-13385 published by MITRE/NVD, describing an Improper Validation of Integrity Check Value (CWE-354) and Improper Certificate Validation (CWE-295) flaw in certain ASUS router models.
  • CVE-2026-13385 record last modified in NVD with refined CVSS v4.0 scoring (9.5, CRITICAL).
  • ASUS firmware patches for the affected 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series are available at time of disclosure; ASUS advises immediate update via its Security Advisory portal.
  • Threat ingested into the TL-Intel Harness backlog via the GBHackers RSS feed for hunt/research processing (TL-2026-1617).
  • GBHackers publishes a public-facing article summarizing the vulnerability, its MITM/command-execution impact, and ASUS's patch guidance.
  • NVD/aggregator tracking (OffSeq Threat Radar) shows a further record update on the public-disclosure date, coinciding with GBHackers media coverage.

Sources cited for Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM

Detection coverage for TL-2026-1617

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1617 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats