
🚨 SECURITY UPDATE: ASUS patches four router firmware flaws (disclosed 7 Oct 2026). 🔸 CVE-2026-14911 (CVSS 4.0 9.3): XSS via a crafted URL. An unauthenticated attacker needs an already logged-in admin to click the link, then can read DOM data, change settings, or cause a denial of service. 🔸 CVE-2026-19386 (CVSS 4.0 9.3): stack buffer overflow through an oversized configuration upload that can lead to code execution — but only for an authenticated admin with adjacent network access, not a pre-auth WAN RCE. 🔸 CVE-2026-16528 (CVSS 4.0 8.4): DDNS credentials written into system logs. 🔸 CVE-2026-19396 (CVSS 4.0 7.7): a predictable PRNG seed can expose an IFTTT pairing token during an admin-initiated pairing session. ⚠️ Not in CISA KEV, and no public PoC confirmed. Fixes are model-specific firmware builds from the ASUS Security Advisory. 🔴 Update your ASUS router firmware now, and avoid opening untrusted links while logged into the admin UI. Full breakdown 👉 https://www.threatwire.tech/research/asus-router-firmware-security-update-october-2026 #CyberSecurity #InfoSec #ASUS #Router


