CVE-2026-14157
CRITICAL
9,4
Source: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.
134
Use of Externally-Controlled Format String
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Potential Impacts:
Read Memory
Modify Memory
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
Not Language-Specific, C, C++, Perl
https://www.asus.com/security-advisory