{"id":20378,"date":"2026-10-04T12:06:23","date_gmt":"2026-10-04T12:06:23","guid":{"rendered":"https:\/\/news.theck1.no\/?p=20378"},"modified":"2026-10-04T12:06:23","modified_gmt":"2026-10-04T12:06:23","slug":"malicious-vpn-config-files-can-let-attackers-run-commands-on-asus-routers","status":"publish","type":"post","link":"https:\/\/news.theck1.no\/?p=20378","title":{"rendered":"Malicious VPN config files can let attackers run commands on Asus routers"},"content":{"rendered":"<p style=\"margin:0 0 1em; padding:0.6em 0.9em; border:1px solid #d0d7de; border-radius:6px; background:#f6f8fa; color:#444; font-size:0.9em;\"><strong>AI-rewritten:<\/strong> This is a summary of an article from Tom&#8217;s Hardware, rewritten by AI (Qwen, running locally) to make it easier to read. The facts come from the original article &ndash; read it for the full story.<\/p>\n<div style=\"margin-bottom:1em; color:#666; font-size:0.9em;\"><strong>Tom&#8217;s Hardware &bull;  Shane Downing  &bull; October 3, 2026<\/strong><\/div>\n<hr\/>\n<p>A malicious VPN configuration file uploaded through an Asus router&#8217;s web interface can allow attackers to execute arbitrary commands, creating a critical security risk that the company has patched. A separate bug involving active debug code lets adversaries bypass security checks to enable Telnet, potentially running commands with root privileges on connected devices. Both vulnerabilities are identified by CVE-2026-14157 and CVE-2026-13313, scoring 9.4 and 8.9 out of 10 on the Common Vulnerability Scoring System (CVSS) 4.0 scale, which measures vulnerability severity.<\/p>\n<p><!--more--><\/p>\n<p>Asus recommends users only import VPN client configuration files from trusted sources because crafted text inside these files can be read as formatting instructions rather than plain data. While VPNs are commonly used to bypass filters on personal devices, this specific risk applies when owners upload configuration files directly into the router itself. The Telnet flaw requires enabling the service first before running commands that could impact the network, and Asus advises against running scripts or tools from untrusted sources within the local network.<\/p>\n<p>In addition to the router fixes, updates were released for 13 motherboards where a physically proximate attacker could read or write arbitrary system memory by inserting a specially crafted device. This flaw affects many of Asus&#8217;s Z390 and C246 motherboards and is rated high severity at 7.0 out of 10. Users are advised to find firmware updates on Asus&#8217;s support page, though devices that have reached end of life will not receive new patches. For those affected routers, Asus suggests using strong, unique login and Wi-Fi passwords as a mitigation strategy.<\/p>\n<div style=\"margin-top:2em; padding:1em; border-left:4px solid #0073aa; background:#f5f7fa;\">\n<p style=\"margin:0;\"><strong>Source:<\/strong> Tom&#8217;s Hardware &bull;  Shane Downing  &bull; October 3, 2026<\/p>\n<p style=\"margin:0.5em 0 0;\"><a href=\"https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/malicious-vpn-config-files-can-let-attackers-run-commands-on-asus-routers-companys-patch-also-fixes-a-bug-that-lets-a-logged-in-attacker-switch-on-telnet-with-root-access\" target=\"_blank\" rel=\"noopener\">Read the original article at Tom&#8217;s Hardware &rarr;<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>AI-rewritten: This is a summary of an article from Tom&#8217;s Hardware, rewritten by AI (Qwen, running locally) to make it easier to read. The facts come from the original article &ndash; read it for the full story. Tom&#8217;s Hardware &bull; Shane Downing &bull; October 3, 2026 A malicious VPN configuration file uploaded through an Asus<\/p>\n<p class=\"more-link\"><a href=\"https:\/\/news.theck1.no\/?p=20378\" class=\"themebutton2\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-20378","post","type-post","status-publish","format-standard","hentry","category-it-hardware"],"_links":{"self":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts\/20378","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20378"}],"version-history":[{"count":0,"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts\/20378\/revisions"}],"wp:attachment":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20378"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20378"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}