Threat Advisory

ASUS Control Center Flaw Lets Attackers Gain Full Admin Control

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-75754 (CVSS 10.0): A critical unauthenticated vulnerability in ASUS Control Center Enterprise allows remote attackers to gain complete administrative/root-level control of the affected system. The flaw involves a chain of missing authentication, SSRF, and hard-coded credentials that can expose an encryption key and enable access to an SSH service on TCP port 2222, ultimately providing a root shell. Because ASUS Control Center centrally manages servers, workstations, and other devices, compromise of the management server could potentially allow attackers to control the broader managed environment. The vulnerability affects ASUS Control Center Enterprise 4.0.0.2 and earlier.

RECOMMENDATION:

We recommend you to update ASUS Control Center Enterprise to version 3.1.0.9 or later.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-75754 (CVSS 10.0): A critical unauthenticated vulnerability in ASUS Control Center Enterprise allows remote attackers to gain complete administrative/root-level control of the affected system. The flaw involves a chain of missing authentication, SSRF, and hard-coded credentials that can expose an encryption key and enable access to an SSH service on TCP port 2222, ultimately providing a root shell. Because ASUS Control Center centrally manages servers, workstations, and other devices, compromise of the management server could potentially allow attackers to control the broader managed environment. The vulnerability affects ASUS Control Center Enterprise 4.0.0.2 and earlier.

RECOMMENDATION:

We recommend you to update ASUS Control Center Enterprise to version 3.1.0.9 or later.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu