Threat reportVulnerabilityTL-2026-1617
Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command Execution
Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM (TL-2026-1617) is a critical-severity software vulnerability scored CVSS 9.5, first published 2026-07-22. It has no confirmed attribution, affects ASUS Router (multiple models sharing affected firmware series), references 1 CVE (CVE-2026-13385), maps to 15 MITRE ATT&CK techniques (T1046, T1059, T1090), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 9.5/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-1617
- Threat ID
- TL-2026-1617
- Severity
- CRITICAL
- CVSS
- 9.5 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- consumer, smallofficehomeoffice, telecoms, criticalinfrastructureedge
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
How Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM works
CVE-2026-13385 (CVSS 4.0: 9.5, CRITICAL) is an improper integrity-check-value validation and improper certificate validation flaw in certain ASUS router firmware series (3.0.0.4_386, 3.0.0.4_388, 3.0.0.6_102) that allows a network-adjacent man-in-the-middle attacker to spoof a firmware/update server and trick the router into downloading and executing arbitrary commands. ASUS has released patched firmware; no public PoC or confirmed active exploitation has been reported.
CVE-2026-13385 is a critical improper-validation vulnerability affecting certain ASUS router firmware builds in the 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. The root cause is dual: (1) CWE-354 Improper Validation of Integrity Check Value — the router firmware/update or configuration-sync client does not correctly validate a cryptographic integrity check (e.g. checksum/signature) on data received from a remote server, and (2) CWE-295 Improper Certificate Validation — the same client fails to properly validate the TLS certificate presented by that remote server. Combined, these defects mean the router's update/sync mechanism can be tricked into trusting a server that is not the legitimate ASUS/cloud endpoint, provided the attacker can position themselves as a man-in-the-middle (MITM) on the network path between the router and that server — e.g. via ARP/DNS spoofing on the LAN, a rogue access point, a compromised upstream ISP hop, or interception on an untrusted network the router's WAN traverses.
An attacker who achieves this MITM position can stand up a spoofed server that mimics the expected update/response payload. Because the router does not verify server identity (invalid/self-signed/mismatched certificate accepted) and does not verify payload integrity (a manipulated or unsigned blob passes the check), the spoofed server can supply a malicious payload that the router downloads and executes as a command — i.e., the flaw provides a direct path from network-level interception to command execution on the device, with no user interaction and no authentication required (CVSS 4.0 vector: AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — network vector, low complexity, attack requirements present [MITM position needed], no privileges, no user interaction, high impact to confidentiality/integrity/availability of both the vulnerable system and any subsequent system it can reach).
Post-exploitation impact on a compromised SOHO/consumer router is severe given its position as the network's default gateway: full device takeover, persistent implant/backdoor installation, DNS hijacking of every downstream client, further traffic interception (defeating the very trust boundary the router is meant to protect), pivoting to internal LAN hosts, and recruitment into a router/IoT botnet for DDoS or proxy (residential-proxy / anonymization) infrastructure — impact patterns consistent with historical ASUS router compromise campaigns (e.g. the 2025 GreyNoise-documented stealthy ASUS backdoor campaign affecting thousands of devices, which is a separate incident/CVE but illustrates the exploitation ceiling for this device class).
As of this writing there is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation; the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. ASUS has already shipped patched firmware for the affected series and — per its Product Security Incident Response practice, which follows ISO/IEC 29147:2018 (vulnerability disclosure) and ISO/IEC 30111:2019 (vulnerability handling) — strongly advises all affected-model owners to update immediately. Because exploitation requires a MITM position, the primary practical exposure window is for devices whose WAN/administrative traffic traverses untrusted or attacker-influenced network segments before the firmware update is applied.
MITRE ATT&CK techniques used in TL-2026-1617
Discovery
T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Command and Control
T1090 Proxy; T1102 Web Service
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1498 Network Denial of Service; T1565 Data Manipulation
defense-impairment
Persistence
T1554 Compromise Host Software Binary; T1556 Modify Authentication Process
credential-access
Credential Access
Collection
Resource Development
T1584 Compromise Infrastructure
Reconnaissance
Affected products and versions in Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM
- ASUS — Router (multiple models sharing affected firmware series)
Vulnerable versions: 3.0.0.4_386; 3.0.0.4_388; 3.0.0.6_102
Fixed in: Patched firmware released by ASUS post-2026-07-15 addressing CVE-2026-13385 (see ASUS Security Advisory for model-specific build numbers)
Remediation for Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM
Patches
- Apply the ASUS Security Advisory firmware update for CVE-2026-13385 (see ASUS Security Advisory portal, asus.com/security-advisory)
Immediate actions
- Update all affected ASUS router models to the patched firmware release addressing CVE-2026-13385
- Avoid connecting the router's WAN interface or administrative sessions to untrusted or public networks where a MITM position is achievable until patched
- Restrict/disable remote administration and any cloud-sync/auto-update client where feasible while awaiting patch confirmation
- Verify current firmware version against the affected series (3.0.0.4_386, 3.0.0.4_388, 3.0.0.6_102) via the router admin UI
Workarounds
- If immediate patching is not possible, disable remote/cloud-based firmware update and configuration-sync features and perform manual, verified firmware installation from the official ASUS support site
Longer-term hardening
- Enforce certificate pinning / strict TLS validation for all device-to-cloud and firmware-update channels
- Cryptographically sign and verify update payloads with a robust integrity check independent of TLS trust
- Deploy network segmentation isolating router management interfaces from general LAN/WAN traffic
- Monitor router DNS and outbound configuration for unauthorized changes indicative of MITM tampering
- Maintain an asset inventory of ASUS router models/firmware versions to accelerate future patch rollouts
CVEs associated with Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM
CVE-2026-13385
Weaknesses (CWE) in Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM
Timeline of Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM
- CVE-2026-13385 identifier reserved by MITRE's CVE Numbering Authority process, roughly three weeks ahead of public disclosure.
- Threat-intelligence aggregators (OffSeq Threat Radar, TheHackerWire) publish technical summaries of CVE-2026-13385 including CWE mapping and CVSS v4.0 vector.
- INCIBE-CERT publishes an early-warning advisory for CVE-2026-13385, confirming CVSS 9.5 CRITICAL classification and affected firmware series.
- CVE-2026-13385 published by MITRE/NVD, describing an Improper Validation of Integrity Check Value (CWE-354) and Improper Certificate Validation (CWE-295) flaw in certain ASUS router models.
- CVE-2026-13385 record last modified in NVD with refined CVSS v4.0 scoring (9.5, CRITICAL).
- ASUS firmware patches for the affected 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series are available at time of disclosure; ASUS advises immediate update via its Security Advisory portal.
- Threat ingested into the TL-Intel Harness backlog via the GBHackers RSS feed for hunt/research processing (TL-2026-1617).
- GBHackers publishes a public-facing article summarizing the vulnerability, its MITM/command-execution impact, and ASUS's patch guidance.
- NVD/aggregator tracking (OffSeq Threat Radar) shows a further record update on the public-disclosure date, coinciding with GBHackers media coverage.
Sources cited for Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM
- Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
- CVE-2026-13385 | INCIBE-CERT | INCIBE
- CVE-2026-13385: CWE-354: Improper Validation of Integrity Check Value in ASUS Router - Threat Radar - OffSeq.com
- CVE-2026-13385 - Vulnerability - TheHackerWire
- ASUS Security Advisory | Latest Vulnerability Update
- NVD - CVE-2026-13385
- CISA Known Exploited Vulnerabilities Catalog
- ASUS Official Statement on Recent Reports Regarding Router Security
- GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
- Asus Router Vulnerability: Thousands of Devices Hacked - Fing
- Top ASUS routers have serious security flaws that could let hackers hijack your device - TechRadar
- Asus warns of new security flaw affecting AiCloud routers - TechRadar
Detection coverage for TL-2026-1617
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1617 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.