Out-of-Bounds Write Vulnerability in ASUS FA507NU and FA507NV BIOS
CVE-2026-19398

6.8MEDIUM

Key Information:

Vendor

Asus

Vendor
CVE Published:
27 August 2026

What is CVE-2026-19398?

The SmiFlash SMM module in the BIOS of ASUS FA507NU and FA507NV devices is vulnerable to an out-of-bounds write condition. This can be triggered by a local administrator sending a crafted software SMI request with an oversized length value. Successfully exploiting this vulnerability may lead to system crashes (BSOD) and potential BIOS corruption, significantly impacting system stability and usability. Users are advised to apply the latest security updates from ASUS to mitigate this vulnerability.

Affected Version(s)

FA507NU 318

FA507NV 318

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hex2mem
.