CVE-2026-75754
10.0ASUS · Control Center Enterprise (ACC)
A critical flaw in ASUS Control Center Enterprise allows unauthenticated attackers to obtain encryption keys, enable SSH, and gain root access via hardcoded credentials.
Executive summary
An unauthenticated remote code execution vulnerability in ASUS Control Center Enterprise poses a catastrophic risk to the entire managed network infrastructure.
Vulnerability
This vulnerability combines missing authentication for critical functions, Server-Side Request Forgery, and the use of hardcoded credentials. An unauthenticated attacker can exploit these flaws to extract encryption keys, enable SSH access, and ultimately execute commands as root on the target system.
Business impact
The potential impact of this vulnerability is total system compromise. Because ASUS Control Center is designed for centralized management, a successful exploit grants an attacker full administrative control over all connected servers, workstations, and PCs within the organization. With a CVSS score of 10.0, this represents the highest level of risk, leading to potential data exfiltration, permanent data loss, and complete loss of integrity across the managed IT environment.
Remediation
Immediate Action: Update ASUS Control Center Enterprise (ACC) to the latest available version provided by the vendor. Consult the official ASUS security advisory for specific patch installation instructions.
Proactive Monitoring: Monitor network traffic for unauthorized HTTP requests directed at the Control Center and investigate any unexpected creation of SSH sessions on port 2222.
Compensating Controls: Restrict network access to the Control Center interface to trusted administrative subnets only. Implement a Web Application Firewall to block suspicious requests that may attempt to trigger the SSRF or authentication bypass mechanisms.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability is classified as critical due to the ease of exploitation and the absolute control it grants an attacker over the managed infrastructure. Organizations must prioritize immediate patching or isolate the affected software from the network until a secure version is deployed. Failure to address this flaw leaves the entire managed device fleet vulnerable to full remote takeover.
More ASUS CVEs
Sources
Originally found and disclosed by Niels Teusink - Eye Security, per the CVE Program record.