CVE detail
CVE-2026-12960
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App ' section on the ASUS Security Advisory for more information.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 4.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- https://www.asus.com/security-advisory/www.asus.com
No excerpt available.
Vendor Advisorywww.asus.comJul 3, 2026, 3:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.80 · max 0 stars
- l0lsec/CVE-2026-12960Medium confidencegithubRepository topic discovery0 starsDiscovered Jul 25, 2026, 8:51 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-57848CVSS 6.8 · Medium
Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts th…
- CVE-2026-54318CVSS 7.1 · High
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with n…
- CVE-2025-68713CVSS 8.0 · High
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no per…
- CVE-2026-44279CVSS 5.5 · Medium
An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all ve…
- CVE-2026-3291CVSS 6.9 · Medium
Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing…
- CVE-2025-15464CVSS 7.5 · High
Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.