---
id: CVE-2026-13313
title: >-
  An Active Debug Code vulnerability in certain ASUS router models allows a
  remote authenticated user, via a crafted HTTP request, to bypass security
  mechanisms and enable the Telnet service, thereby executing arbitrary commands
  with root …
summary: >-
  An Active Debug Code vulnerability in certain ASUS router models allows a
  remote authenticated user, via a crafted HTTP request, to bypass security
  mechanisms and enable the Telnet service, thereby executing arbitrary commands
  with root …
severity: high
cvss: 8.9
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'
cwe:
  - CWE-489
vendor: ASUS
product: Router
affected:
  - Router 3.0.0.4_386 series
  - Router 3.0.0.4_388 series
  - Router 3.0.0.6_102 series
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T02:16:53.817'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13313'
references:
  - url: 'https://www.asus.com/security-advisory'
    label: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-01T02:34:58.239Z'
---

## Overview

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router.
Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
