CVE-2026-75754

10.0

ASUS · Control Center Enterprise (ACC)

A critical flaw in ASUS Control Center Enterprise allows unauthenticated attackers to obtain encryption keys, enable SSH, and gain root access via hardcoded credentials.

Executive summary

An unauthenticated remote code execution vulnerability in ASUS Control Center Enterprise poses a catastrophic risk to the entire managed network infrastructure.

Vulnerability

This vulnerability combines missing authentication for critical functions, Server-Side Request Forgery, and the use of hardcoded credentials. An unauthenticated attacker can exploit these flaws to extract encryption keys, enable SSH access, and ultimately execute commands as root on the target system.

Business impact

The potential impact of this vulnerability is total system compromise. Because ASUS Control Center is designed for centralized management, a successful exploit grants an attacker full administrative control over all connected servers, workstations, and PCs within the organization. With a CVSS score of 10.0, this represents the highest level of risk, leading to potential data exfiltration, permanent data loss, and complete loss of integrity across the managed IT environment.

Remediation

Immediate Action: Update ASUS Control Center Enterprise (ACC) to the latest available version provided by the vendor. Consult the official ASUS security advisory for specific patch installation instructions.

Proactive Monitoring: Monitor network traffic for unauthorized HTTP requests directed at the Control Center and investigate any unexpected creation of SSH sessions on port 2222.

Compensating Controls: Restrict network access to the Control Center interface to trusted administrative subnets only. Implement a Web Application Firewall to block suspicious requests that may attempt to trigger the SSRF or authentication bypass mechanisms.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability is classified as critical due to the ease of exploitation and the absolute control it grants an attacker over the managed infrastructure. Organizations must prioritize immediate patching or isolate the affected software from the network until a secure version is deployed. Failure to address this flaw leaves the entire managed device fleet vulnerable to full remote takeover.

More ASUS CVEs

Sources

Originally found and disclosed by Niels Teusink - Eye Security, per the CVE Program record.