Critical ASUS Control Center Bug Lets Attackers Gain Admin Access
Key Takeaways A critical vulnerability in ASUS Control Center Enterprise (ACC) allows unauthenticated remote attackers to gain full administrative control. The flaw, tracked as CVE-2026-75754,...
Key Takeaways
- A critical vulnerability in ASUS Control Center Enterprise (ACC) allows unauthenticated remote attackers to gain full administrative control.
- The flaw, tracked as CVE-2026-75754, carries a maximum CVSS 4.0 score of 10.0.
- Attackers can exploit a chain of weaknesses, including missing authentication, a server-side request forgery (SSRF), and hard-coded credentials, to achieve root access.
- All versions of ACC Enterprise up to and including 4.0.0.2 are affected.
- ASUS has released a patch, urging users to update to version 3.1.0.9 or later immediately.
Max-Severity ASUS Control Center Flaw Poses Enterprise-Wide Risk
ASUS has released an urgent security update for its Control Center Enterprise (ACC) software after cybersecurity researchers uncovered a critical vulnerability that could allow remote attackers to achieve complete administrative control over the platform and all managed devices. The exploit requires no authentication or user interaction, presenting a severe risk to organizations utilizing the central management solution.
Table Of Content
Designated as CVE-2026-75754, the vulnerability has been assigned the highest possible CVSS 4.0 score of 10.0. This score underscores the ease with which the flaw can be exploited over a network and the devastating impact an attacker could achieve once inside an organization’s IT infrastructure.
Chained Vulnerabilities Lead to Root Access
The path to compromise involves a sophisticated chain of three distinct security weaknesses within the ASUS Control Center. The initial point of failure is a critical function within ACC that lacks proper authentication. This oversight means that sensitive operations can be triggered by any entity capable of reaching the service over the network, bypassing intended security controls.
This authentication gap is then leveraged by a server-side request forgery (SSRF) vulnerability. An attacker can craft a specific HTTP request to trick the system into revealing its internal encryption key. Upon successful retrieval of this key, a local service on the host automatically activates an SSH listener on TCP port 2222, effectively creating a covert access point into the machine.
The final, and perhaps most critical, element of this exploit chain involves hard-coded credentials embedded directly within the ASUS Control Center software. With the encryption key in hand, attackers can use these fixed credentials to log into the newly opened SSH port, gaining a full root shell—the highest level of system access available on the compromised machine.
Once root access is established, attackers possess the capability to read, modify, or delete any data stored within the ACC platform. Given that ACC is designed to centrally manage extensive fleets of servers, PCs, and workstations, a single compromised instance could grant attackers remote control over an entire corporate IT environment, posing an existential threat to data integrity and operational continuity.
Affected Versions and Patch Availability
The vulnerability impacts all versions of ASUS Control Center Enterprise up to and including 4.0.0.2. ASUS strongly advises all organizations running the software to update immediately to version 3.1.0.9 or later. Further details regarding the fix are available on ASUS’s official Security Advisory page.
What You Should Do
- Update Immediately: Organizations should prioritize updating ASUS Control Center Enterprise to version 3.1.0.9 or later without delay.
- Network Isolation: If immediate patching is not feasible, isolate ACC management interfaces from public networks to limit exposure.
- Block Port 2222: Implement firewall rules to block both inbound and outbound traffic on TCP port 2222 as an interim mitigation.
- Audit for SSH Listeners: Regularly audit hosts for unexpected SSH listeners to detect potential compromise attempts or successful exploitation.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.