ASUS published CVE-2026-75754 on September 4, 2026. This ASUS Control Center vulnerability earns a maximum CVSS score of 10.0. It lets an unauthenticated attacker gain a root shell and seize an entire fleet of managed machines.
- CVE: CVE-2026-75754
- CVSS: 10 (Critical · CVSSv4)
- Product: ASUS Control Center Enterprise (ACC)
- Affected: ≤ 4.0.0.2
- Impact: Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard...
- Status: No confirmed exploitation yet
- EPSS: 0.2% (30-day)
- Action: See vendor advisory
Why this matters
ASUS Control Center manages servers, PCs, and workstations across a company. So one flaw here can expose an entire environment. The bug needs no login and no user interaction. That combination makes this ASUS Control Center vulnerability about as serious as a flaw can get. The full CVSS vector rates confidentiality, integrity, and availability all at high.
How the attack works
The flaw chains three weaknesses. First, a missing authentication check lets an attacker request the encryption key over HTTP. As ASUS puts it, an unauthorized user can “obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222.”
Next, the attacker logs in with hard-coded credentials. That step returns a root shell. From there, the intruder reads, writes, and deletes data and controls every managed device. A server-side request forgery weakness rounds out the chain.
Exploitation status
No public proof-of-concept exploit and no in-the-wild attacks have been confirmed so far.
Affected versions
All ASUS Control Center builds before v3.1.0.9 are affected. The count of exposed deployments is not publicly reported.
Patch and mitigation steps
Update ASUS Control Center to v3.1.0.9 or later right away. ASUS “strongly recommends that all users immediately update.” Review the official ASUS Security Advisory for details. Until you patch, restrict network access to the management interface and watch for unexpected SSH activity on port 2222.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!