CVE-2026-12960 is an improper export of Android application components vulnerability in the ASUS Router Android App. A third-party application installed on the same Android device can send a crafted Intent to an exported component in the ASUS Router App and cause the application to open an attacker-specified URL. The issue stems from unsafe exposure of Android app components to other local applications without sufficient restriction or validation of externally supplied Intent data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a working local Android exploit PoC for CVE-2026-12960, an improper export of Android application components issue in the ASUS Router app (com.asus.aihome). The vulnerability is an exported Baidu Push SDK service, com.baidu.android.pushservice.CommandService, exposed without an android:permission requirement. Any app on the same device can call startService() and pass a crafted PublicMsg Parcelable. The PoC reconstructs the expected Parcelable field order and uses the privatenotification.CLICK action to make the ASUS app launch attacker-controlled URIs. Main code is in poc/ExploitCommandService.java, which launches the target app to foreground and then dispatches six payloads demonstrating browser phishing, SMS composition, dialer launch, email composition, Play Store redirect, and map redirect. poc/PublicMsg.java implements the Parcelable exactly as required by the target service. poc/AndroidManifest_PoC.xml defines a zero-permission PoC app with a launcher activity and a triggerable broadcast receiver. poc/poc_commandservice_exploit.sh automates three phases: access verification via ADB shell, APK build/sign/install, and exploit execution/log collection. The README also documents a broader capability via mOpenType=2, where attacker-controlled mPkgContent is parsed with Intent.parseUri(), potentially enabling arbitrary intent injection, startActivity, or sendBroadcast behavior. Overall, this is a legitimate operational PoC for a local privilege/trust abuse scenario on Android, not a remote exploit or mere detector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.