External risk intelligence

ASUS Router Format String Vulnerability Allows Command Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-14157

The vulnerability exists in the web management interface of a router. While access requires authentication, router management interfaces are frequently exposed to the internet or reachable via remote management features, making them a common target for external network-based access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in ASUS router modules that could allow a remote, authenticated user to run unauthorized commands by uploading a specially crafted file through the device's web management interface. This vulnerability leverages an externally controlled format string, which could enable attackers to execute commands on the affected devices. The main concern is to confirm if this specific technology is in use within our environment and to what extent.

  • Attackers can run commands with authenticated access.
  • Confirms if ASUS routers are in our environment.
  • Assess relevance and exposure of affected ASUS devices.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access to the ASUS router's web management interface can upload a specially crafted file. This file can then be processed in a way that allows the attacker to execute arbitrary commands on the router, leading to a compromise of the device.

  • Requires authenticated access.
  • Triggered by uploading a crafted file.
  • Leads to command execution.

Live Threat

Current exploitation, exposure, and threat context

A remote authenticated user could execute arbitrary commands by uploading a crafted file through the ASUS Router's web management interface. This could impact system data and service behavior.

  • System commands and configuration data at risk.
  • Via uploaded crafted file on web interface.
  • Potential for unauthorized system control.

Operational Fix

Recommended remediation, mitigation, and detection steps

Responsible teams, likely including infrastructure, platform, and security, must first identify all ASUS router instances, confirm their reachability and business criticality, and then locate the accountable owner. Remediation planning should then be based on this risk assessment.

  • Infrastructure and platform teams own remediation.
  • Verify router reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What are ASUS router modules and how are they used?

ASUS router modules are the underlying software components that manage network routing, wireless traffic, and administrative tasks on ASUS networking hardware. They provide the core functionality for your home or office internet connectivity, including the web-based management interface used to configure device settings and security features.

What is the CWE-134 vulnerability in CVE-2026-14157?

CWE-134 refers to an 'Externally Controlled Format String' weakness. This occurs when an application uses user-supplied input—in this case, a file upload—directly as a formatting instruction for internal functions. If not handled carefully, this allows the input to manipulate the program's execution, potentially leading to unauthorized command execution.

How is this command execution triggered?

An attacker triggers this by uploading a specially crafted file through the web management interface. Importantly, this vulnerability is not triggered by simply visiting the web interface or by standard network traffic; it requires a specific, malicious file upload action to reach the vulnerable code path.

Why does Halo Surface Signal categorize this as an external threat?

Halo Surface Signal labels this as external because the vulnerability resides in the web management interface of a router. Even though it requires authentication, these interfaces are often exposed to the internet or accessible via remote management features, which significantly increases the risk of unauthorized external access.

What is the first step if I use ASUS routers?

Your priority is to identify all ASUS router instances within your network environment. Once identified, verify their reachability and business criticality. Coordinate with your infrastructure or platform teams to confirm if your devices are currently reachable from untrusted networks and to track updates from the vendor.

References