CVE-2026-19396: High severity ASUS RT-BE57 router vulnerability
A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via observed values from an administrator-initiated IFTTT pairing session.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
ASUS RT-BE57 deployments are exposed when an administrator initiates an IFTTT pairing session and a nearby unauthenticated user can observe values from that session.
What does an attacker need to exploit it?
The attacker must be nearby, unauthenticated, and able to observe values from an administrator-initiated IFTTT pairing session. They can use the predictable PRNG seed to derive the pairing token.
What access could exploitation provide?
A successful attacker can read or modify router settings using the derived pairing token.