CVE-2026-19397

7.7

ASUS · Control Center Express Agent

A missing authentication vulnerability in the ASUS Control Center Express Agent allows an unauthenticated nearby attacker to gain host control if an active user session exists.

Executive summary

A missing authentication vulnerability in ASUS Control Center Express Agent allows unauthenticated nearby attackers to compromise host systems, necessitating an immediate update to version 1.7.24.

Vulnerability

The software fails to perform proper authentication for a critical function, allowing an unauthenticated attacker on the local network segment to interact with and control the agent. This flaw specifically requires the target host to have an active login session, which serves as the primary technical constraint for successful exploitation.

Business impact

Successful exploitation grants an attacker full control over the host system, leading to potential data exfiltration, system manipulation, or unauthorized administrative actions. With a CVSS score of 7.7, this is a high severity vulnerability that poses a significant risk to organizational assets and operational integrity.

Remediation

Immediate Action: Update the ASUS Control Center Express Agent to version 1.7.24 or later immediately to resolve the authentication bypass.

Proactive Monitoring: Monitor network traffic for unauthorized or anomalous connection attempts directed at the Control Center Express Agent ports.

Compensating Controls: Restrict network access to the agent port via host-based firewalls to ensure only authorized management workstations can communicate with the service.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete host takeover, organizations should prioritize patching the ASUS Control Center Express Agent across all deployments. Administrators should verify the version currently in use and apply the version 1.7.24 update as soon as possible to neutralize this high-risk authentication flaw.

More ASUS CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by 0x0dee, per the CVE Program record.