---
id: CVE-2026-12960
title: >-
  An Improper Export of Android Application Components vulnerability in ASUS
  Router App allows a third-party application on the same device to send a
  crafted Intent that causes ASUS Router App to open an specified URL.

  Refer to the '

  Secur…
summary: >-
  An Improper Export of Android Application Components vulnerability in ASUS
  Router App allows a third-party application on the same device to send a
  crafted Intent that causes ASUS Router App to open an specified URL.

  Refer to the '

  Secur…
severity: medium
cvss: 6
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'
cwe:
  - CWE-926
vendor: ASUS
product: Router app
affected:
  - router_app through 1.0.0.9.71
published: '2026-07-03'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T09:16:37.343'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12960'
references:
  - url: 'https://www.asus.com/security-advisory/'
    label: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00159
epssPercentile: 0.04295
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/l0lsec/CVE-2026-12960'
  checkedAt: '2026-09-25T08:20:49.864Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-06T15:42:42.380949Z'
cvssSource: cna
ingestedAt: '2026-09-17T09:14:58.447Z'
---

## Overview

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL.
Refer to the '
Security Update for ASUS Router Android App ' section on the ASUS Security Advisory for more information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
