Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.asus.com/security-advisory |
|
Wed, 07 Oct 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Authenticated Log Injection Reveals DDNS Credentials in ASUS Routers |
Wed, 07 Oct 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information. | |
| First Time appeared |
Asus
Asus router |
|
| Weaknesses | CWE-532 | |
| CPEs | cpe:2.3:a:asus:router:3.0.0.4.386_series:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.4.388_series:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.6.102_series:*:*:*:*:*:*:* |
|
| Vendors & Products |
Asus
Asus router |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ASUS
Published:
Updated: 2026-10-07T02:02:43.107Z
Reserved: 2026-07-22T07:37:52.529Z
Link: CVE-2026-16528
No data.
Status : Received
Published: 2026-10-07T02:16:57.730
Modified: 2026-10-07T02:16:57.730
Link: CVE-2026-16528
No data.
OpenCVE Enrichment
Updated: 2026-10-07T03:45:10Z
-
CWE-532
Insertion of Sensitive Information into Log File