# Asus patches router flaws enabling command execution and root access

_Published Saturday, October 3, 2026 at 9:06 AM EDT · Security · Latest · Tier 2 — Notable_

![An Asus RT-BE92U router with four antennas on wooden furniture, next to a lamp and some books — Primary](https://cdn.mos.cms.futurecdn.net/6mmVqfQjXAQVMLwxBZ5SQV-617-80.jpg)

Asus has patched two router vulnerabilities that can let attackers execute commands, Tom's Hardware reports. One flaw involves a crafted VPN configuration file imported through the web management interface; the other uses active debug code to enable Telnet and potentially run commands with root privileges.

Both affect firmware series 3.0.0.6_102. The Telnet flaw also affects series 3.0.0.4_386 and 3.0.0.4_388. The VPN attack requires a user or logged-in attacker to upload the malicious configuration; it concerns the router's VPN client rather than VPN apps on computers or phones.

Asus recommends firmware updates and importing configurations only from trusted sources. Routers that have reached end of life will receive no new firmware.

## Sources

- [Tom's Hardware](https://www.tomshardware.com/tech-industry/cyber-security/malicious-vpn-config-files-can-let-attackers-run-commands-on-asus-routers-companys-patch-also-fixes-a-bug-that-lets-a-logged-in-attacker-switch-on-telnet-with-root-access)

---
Canonical: https://techandbusiness.org/newswire/SxpZYdze2mhotTJ8tFbIyf
Published: 2026-10-03T13:06:55.916Z
Story chronology: 2026-10-03T12:30:00.000Z
Retrieved: 2026-10-03T15:47:20.105Z
Publisher: Tech & Business (techandbusiness.org)
