{
  "id": 11683494,
  "title": "Malicious VPN config files can let attackers run commands on Asus routers",
  "url": "https://urgent.news/2026/10/03/malicious-vpn-config-files-can-let-attackers-run-commands-on-asus",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T12:30:00.000Z",
  "source": {
    "name": "Tom's Hardware",
    "slug": "tom-s-hardware",
    "url": "https://www.tomshardware.com/tech-industry/cyber-security/malicious-vpn-config-files-can-let-attackers-run-commands-on-asus-routers-companys-patch-also-fixes-a-bug-that-lets-a-logged-in-attacker-switch-on-telnet-with-root-access"
  },
  "original_language": "en",
  "account": "Malicious VPN configuration files uploaded through an Asus router's web interface could allow attackers to execute arbitrary commands on the device, a critical security risk that the company has patched. A second bug, enabled through debug code, could bypass security checks to allow Telnet commands with potential root privileges. Asus advises users to only import VPN files from trusted sources. The vulnerabilities, CVE-2026-14157 and CVE-2026-13313, have high severity scores on the CVSS scale. Users are advised to update their firmware to version 3.0.0.6_102, and for affected motherboards, BIOS versions 1502 or 2203. Asus also recommends strong, unique passwords and discourages running untrusted scripts.",
  "summary": "Until routers on Asus’s 3.0.0.6_102 firmware are updated, the company says not to import untrusted VPN files.",
  "key_points": [
    "Malicious VPN config files allow command execution on Asus routers",
    "Debug code bypasses security checks for Telnet commands",
    "Asus advises firmware update to version 3.0.0.6102"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}