ASUS Patches Critical Flaws Letting Attackers Seize Control Center Enterprise and Nearby Hosts

ASUS has released security updates fixing critical vulnerabilities across two of its device-management products, including a maximum-severity flaw that let an unauthenticated attacker gain root access to the server managing an organization’s fleet of PCs and workstations.

A Chained Path to Root on Control Center Enterprise

The more severe issue, CVE-2026-75754, carries a CVSS score of 10.0 and affects ASUS Control Center Enterprise (ACC) version 4.0.0.2 and all earlier releases. It stems from a chain of missing authentication, server-side request forgery and hard-coded credentials: an attacker can send a crafted HTTP request to obtain the system’s encryption key, which causes a local service to open SSH on port 2222, then use hard-coded credentials to obtain a root shell on the ACC server. Successful exploitation gives an attacker full control of the platform, including the ability to read, modify or delete stored data and remotely manage every server, PC and workstation the platform oversees. ASUS published the fix on September 4, 2026.

A Second, Separate Flaw in Control Center Express

ASUS separately patched CVE-2026-19397, a missing-authentication vulnerability in the Control Center Express Agent affecting versions before 1.7.24. The flaw, classified as CWE-306, allows an unauthenticated nearby attacker with a direct connection to the agent to take control of a host that has an active login session, potentially executing code or performing any action available to the logged-in user. ASUS published updates for Control Center Express and its Armoury Crate software, which separately addressed a flaw that could expose a user’s NTLM hash, on September 8, 2026. Neither vulnerability has been reported as actively exploited, but organizations running either platform are advised to update immediately given the scope of access each flaw can grant.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *