AI analysis
CVE-2026-19397 is a missing-authentication flaw (CWE-306) in the ASUS Control Center Express (ACE) Agent, the endpoint component of ASUS's fleet-management software. An unauthenticated user on the adjacent network segment can make a direct connection to the agent and take control of the host, but only while the host has an active login session. Because no credentials are required, the attacker gains full control of the machine — the CVSS 4.0 base score of 7.7 (High) rates confidentiality, integrity, and availability impact on the vulnerable host as High, and related coverage describes unauthenticated attackers obtaining root-level access. Organizations running the ACE Agent on managed ASUS endpoints are affected, particularly where the agent is reachable from untrusted LAN segments. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.2% in 30 days), and ASUS has published a security update addressing it.
What to do: Update the ASUS Control Center Express Agent to the fixed release listed in ASUS's 'Security Update for ASUS Control Center Express Agent' advisory. Until patched, restrict access to the agent's listening interface so only trusted management segments can reach it, since any unauthenticated user on the same network segment can connect. Inventory managed ASUS endpoints for the ACE Agent and confirm whether those hosts are routinely used with active login sessions, as exploitation requires one.
Affected
| ASUS Control Center Express Agent | — |
Estimated exposure
unknown — plausibly no more than tens of thousands of managed endpoints at most — No public install counts, market-share figures, or internet-exposure scans are available for this enterprise-only management agent, which runs solely on hosts enrolled in ASUS Control Center Express and is reachable only via network…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.