CVE-2026-19386

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-07: 310-07
Referenced assets3 URLs
Full discourse3 posts
  • ThreatWire@ThreatWire_

    🚨 SECURITY UPDATE: ASUS patches four router firmware flaws (disclosed 7 Oct 2026). 🔸 CVE-2026-14911 (CVSS 4.0 9.3): XSS via a crafted URL. An unauthenticated attacker needs an already logged-in admin to click the link, then can read DOM data, change settings, or cause a denial of service. 🔸 CVE-2026-19386 (CVSS 4.0 9.3): stack buffer overflow through an oversized configuration upload that can lead to code execution — but only for an authenticated admin with adjacent network access, not a pre-auth WAN RCE. 🔸 CVE-2026-16528 (CVSS 4.0 8.4): DDNS credentials written into system logs. 🔸 CVE-2026-19396 (CVSS 4.0 7.7): a predictable PRNG seed can expose an IFTTT pairing token during an admin-initiated pairing session. ⚠️ Not in CISA KEV, and no public PoC confirmed. Fixes are model-specific firmware builds from the ASUS Security Advisory. 🔴 Update your ASUS router firmware now, and avoid opening untrusted links while logged into the admin UI. Full breakdown 👉 https://www.threatwire.tech/research/asus-router-firmware-security-update-october-2026 #CyberSecurity #InfoSec #ASUS #Router

    00050312
    1.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Four ASUS router vulnerabilities are fixed, including critical XSS flaw CVE-2026-14911 and code execution bug CVE-2026-19386. Update firmware now. #ASUS #ASUSRouter #RouterSecurity #CVE202614911 #CVE202619386 #XSS #FirmwareUpdate #Vulnerability https://securityonline.info/asus-router-vulnerabilities-firmware-update/

    01000263
    13.0K followersView on X
  • CVE@CVEnew

    CVE-2026-19386 A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that ex… https://www.cve.org/CVERecord?id=CVE-2026-19386

    00000546
    58.1K followersView on X

Explore more