Authentication Flaws and SSRF in ASUS Control Center
CVE-2026-75754

10CRITICAL

Key Information:

Vendor

Asus

Vendor
CVE Published:
4 September 2026

What is CVE-2026-75754?

ASUS Control Center is impacted by missing authentication for critical functions, which, combined with server-side request forgery (SSRF) and hard-coded credentials, creates a significant security risk. An attacker can exploit these vulnerabilities to send malicious HTTP requests that allow unauthorized access to sensitive encryption keys. This exploitation could enable the attacker to configure the system to enable SSH on port 2222 and gain root access using the hard-coded credentials. Once inside, attackers can read, write, and delete data on the ASUS Control Center, leading to potential compromise of all associated servers, PCs, and workstations.

Affected Version(s)

Control Center Enterprise (ACC) 0 <= 4.0.0.2

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Niels Teusink - Eye Security
.