CVE-2026-14157

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.

  • Published Oct 1, 2026
  • CVSS 9.4 critical
  • 0.8% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-14157 at the National Vulnerability Database