CriticalCritical vulnerability
CVE-2026-19386 (CVSS 9.3)
NVD · officialPublished Oct 7, 2026Risk 50/100
A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Technical details
CVSS
9.3
AV:AdjacentAC:LowPR:HighUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source