Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19396

Quick assessment

Affected
ASUS Router
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

华硕(ASUS)RT-BE57 路由器中 IFTTT 配对令牌生成所用的伪随机数生成器(PRNG)存在可预测的种子值缺陷,使得未经认证的附近用户能够通过观察管理员发起的 IFTTT 配对会话中的观测值,推导出配对令牌,进而读取或篡改路由器设置。 有关详细信息,请参阅华硕安全公告中的“华硕路由器固件安全更新”部分。

CVSS 7.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19396

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via observed values from an administrator-initiated IFTTT pairing session.Refer to the ' Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
PRNG中使用可预测种子
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ASUS Router 3.0.0.6_102 series -

II. Public POCs for CVE-2026-19396

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19396

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-19396 (1)

Same Patch Batch · ASUS · 2026-10-07 · 4 CVEs total

CVE-2026-14911 9.3 CRITICAL 华硕路由器固件跨站脚本漏洞
CVE-2026-19386 9.3 CRITICAL 华硕路由器配置上传栈溢出漏洞
CVE-2026-16528 8.4 HIGH ASUS路由器日志注入漏洞,泄露DDNS凭据

IV. Related Vulnerabilities

V. Comments for CVE-2026-19396

No comments yet


Leave a comment