ASUS Routers Improper Certificate Validation and Integrity Check Vulnerability Allowing Remote Command Execution

Vulnerability

A vulnerability in certain ASUS router models, related to improper validation of integrity check values and certificates, enables a remote man-in-the-middle (MITM) attacker to make the router download and execute arbitrary commands from a spoofed server. This issue affects ASUS routers running firmware versions 3.0.0.4_386 series, 3.0.0.4_388 series, and 3.0.0.6_102 series.

Impact

Exploitation of this vulnerability allows for remote command execution on the affected router.

Remediation

Users are advised to update to the latest ASUS router firmware. Instructions for updating can be found on the ASUS Support page.

Added: Jul 15, 2026, 3:27 AM
Updated: Jul 15, 2026, 3:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.2
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.