# Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command Execution

> CVE-2026-13385 (CVSS 4.0: 9.5, CRITICAL) is an improper integrity-check-value validation and improper certificate validation flaw in certain ASUS router firmware series (3.0.0.4_386, 3.0.0.4_388, 3.0.0.6_102) that allows a network-adjacent man-in-the-middle attacker to spoof a firmware/update server and trick the router into downloading and executing arbitrary commands. ASUS has released patched firmware; no public PoC or confirmed active exploitation has been reported.

- **Published:** 2026-07-22T00:00:00Z
- **Last reviewed:** 2026-07-22T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1617
- **ID:** TL-2026-1617
- **Severity:** CRITICAL (CVSS 9.5)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-13385

## Description

CVE-2026-13385 is a critical improper-validation vulnerability affecting certain ASUS router firmware builds in the 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. The root cause is dual: (1) CWE-354 Improper Validation of Integrity Check Value — the router firmware/update or configuration-sync client does not correctly validate a cryptographic integrity check (e.g. checksum/signature) on data received from a remote server, and (2) CWE-295 Improper Certificate Validation — the same client fails to properly validate the TLS certificate presented by that remote server. Combined, these defects mean the router's update/sync mechanism can be tricked into trusting a server that is not the legitimate ASUS/cloud endpoint, provided the attacker can position themselves as a man-in-the-middle (MITM) on the network path between the router and that server — e.g. via ARP/DNS spoofing on the LAN, a rogue access point, a compromised upstream ISP hop, or interception on an untrusted network the router's WAN traverses.

An attacker who achieves this MITM position can stand up a spoofed server that mimics the expected update/response payload. Because the router does not verify server identity (invalid/self-signed/mismatched certificate accepted) and does not verify payload integrity (a manipulated or unsigned blob passes the check), the spoofed server can supply a malicious payload that the router downloads and executes as a command — i.e., the flaw provides a direct path from network-level interception to command execution on the device, with no user interaction and no authentication required (CVSS 4.0 vector: AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — network vector, low complexity, attack requirements present [MITM position needed], no privileges, no user interaction, high impact to confidentiality/integrity/availability of both the vulnerable system and any subsequent system it can reach).

Post-exploitation impact on a compromised SOHO/consumer router is severe given its position as the network's default gateway: full device takeover, persistent implant/backdoor installation, DNS hijacking of every downstream client, further traffic interception (defeating the very trust boundary the router is meant to protect), pivoting to internal LAN hosts, and recruitment into a router/IoT botnet for DDoS or proxy (residential-proxy / anonymization) infrastructure — impact patterns consistent with historical ASUS router compromise campaigns (e.g. the 2025 GreyNoise-documented stealthy ASUS backdoor campaign affecting thousands of devices, which is a separate incident/CVE but illustrates the exploitation ceiling for this device class).

As of this writing there is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation; the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. ASUS has already shipped patched firmware for the affected series and — per its Product Security Incident Response practice, which follows ISO/IEC 29147:2018 (vulnerability disclosure) and ISO/IEC 30111:2019 (vulnerability handling) — strongly advises all affected-model owners to update immediately. Because exploitation requires a MITM position, the primary practical exposure window is for devices whose WAN/administrative traffic traverses untrusted or attacker-influenced network segments before the firmware update is applied.

## MITRE ATT&CK

- T1557 Adversary-in-the-Middle
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1554 Compromise Host Software Binary
- T1556 Modify Authentication Process
- T1553 Subvert Trust Controls
- T1557 Adversary-in-the-Middle
- T1046 Network Service Discovery
- T1210 Exploitation of Remote Services
- T1557 Adversary-in-the-Middle
- T1090 Proxy
- T1102 Web Service
- T1498 Network Denial of Service
- T1565 Data Manipulation
- T1584 Compromise Infrastructure
- T1595 Active Scanning

## Sources

- [Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands](https://gbhackers.com/critical-asus-router-flaw/)
- [CVE-2026-13385 | INCIBE-CERT | INCIBE](https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2026-13385)
- [CVE-2026-13385: CWE-354: Improper Validation of Integrity Check Value in ASUS Router - Threat Radar - OffSeq.com](https://radar.offseq.com/threat/cve-2026-13385-cwe-354-improper-validation-of-inte-022c4477d04d4a24)
- [CVE-2026-13385 - Vulnerability - TheHackerWire](https://www.thehackerwire.com/vulnerability/CVE-2026-13385/)
- [ASUS Security Advisory | Latest Vulnerability Update](https://www.asus.com/security-advisory/)
- [NVD - CVE-2026-13385](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-13385)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)
- [ASUS Official Statement on Recent Reports Regarding Router Security](https://www.asus.com/us/news/wbhfio4vqjodds5p/)
- [GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers](https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers)
- [Asus Router Vulnerability: Thousands of Devices Hacked - Fing](https://www.fing.com/news/new-asus-router-vulnerability-attack/)
- [Top ASUS routers have serious security flaws that could let hackers hijack your device - TechRadar](https://www.techradar.com/pro/security/top-asus-routers-have-serious-security-flaws-that-could-let-hackers-hijack-your-device)
- [Asus warns of new security flaw affecting AiCloud routers - TechRadar](https://www.techradar.com/pro/security/asus-warns-of-new-security-flaw-affecting-aicloud-routers-heres-what-we-know)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1617
