Authentication Flaws and SSRF in ASUS Control Center
CVE-2026-75754

10CRITICAL

Key Information:

Vendor

Asus

Vendor
CVE Published:
4 September 2026

What is CVE-2026-75754?

CVE-2026-75754 is a severe vulnerability found in ASUS Control Center, a software solution used primarily for management and control of ASUS hardware within enterprise environments. This vulnerability is characterized by critical authentication flaws, server-side request forgery (SSRF) weaknesses, and the presence of hard-coded credentials. An attacker exploiting this vulnerability could execute unauthorized HTTP requests to retrieve sensitive encryption keys, which in turn, could activate SSH services on the device. This access permits an unauthorized user to log in using the embedded credentials, ultimately achieving a root shell. The implications of this vulnerability are severe, as it effectively grants attackers unchecked access to sensitive data and administrative controls over all connected systems, workstations, and servers within the affected organization.

Potential impact of CVE-2026-75754

  1. Unauthorized System Access: Attackers can gain root-level access to the ASUS Control Center, allowing them to manipulate, read, or delete critical data across all devices connected to the network.

  2. Data Breaches: With unhindered access to sensitive information and system controls, organizations risk severe data breaches that could lead to the exposure of confidential business information and personal data of users.

  3. Remote Control of Company Infrastructure: The vulnerability grants attackers the ability to remotely control all connected PCs and servers, potentially leading to further exploitation, data corruption, or the deployment of additional malicious software within the organization’s IT ecosystem.

Affected Version(s)

Control Center Enterprise (ACC) through 4.0.0.2

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Niels Teusink - Eye Security
.