The ASUS Control Center vulnerability earns a maximum CVSS score of 10.0, allowing unauthenticated attackers to gain a root shell and full remote control over managed machines. This vulnerability is particularly serious due to its ability to expose an entire environment with no login or user interaction required.
The flaw chains three weaknesses: a missing authentication check, hard-coded credentials for logging in, and a server-side request forgery weakness. These vulnerabilities allow attackers to read, write, and delete data and control every managed device. The affected versions of ASUS Control Center are all builds before v3.1.0.9, with no public proof-of-concept exploit or in-the-wild attacks confirmed yet.[/subscribe_to_unlock_form]
The ASUS Control Center vulnerability earns a maximum CVSS score of 10.0, allowing unauthenticated attackers to gain a root shell and full remote control over managed machines. This vulnerability is particularly serious due to its ability to expose an entire environment with no login or user interaction required.
The flaw chains three weaknesses: a missing authentication check, hard-coded credentials for logging in, and a server-side request forgery weakness. These vulnerabilities allow attackers to read, write, and delete data and control every managed device. The affected versions of ASUS Control Center are all builds before v3.1.0.9, with no public proof-of-concept exploit or in-the-wild attacks confirmed yet.[emaillocker id="1283"]
We recommend you to update ASUS Control Center to the version 3.1.0.9 or later.
The following reports contain further technical details:
[/emaillocker]