Authentication Flaws and SSRF in ASUS Control Center
CVE-2026-75754
10CRITICAL
Key Information:
- Vendor
Asus
- Vendor
- CVE Published:
- 4 September 2026
What is CVE-2026-75754?
ASUS Control Center is impacted by missing authentication for critical functions, which, combined with server-side request forgery (SSRF) and hard-coded credentials, creates a significant security risk. An attacker can exploit these vulnerabilities to send malicious HTTP requests that allow unauthorized access to sensitive encryption keys. This exploitation could enable the attacker to configure the system to enable SSH on port 2222 and gain root access using the hard-coded credentials. Once inside, attackers can read, write, and delete data on the ASUS Control Center, leading to potential compromise of all associated servers, PCs, and workstations.
Affected Version(s)
Control Center Enterprise (ACC) 0 <= 4.0.0.2