ZeroHour

CVE-2026-19397

Missing Authentication in ASUS Control Center Express Agent Allows Host Takeover

CVSS 4.0
7.7 high
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-19397 is a missing-authentication flaw (CWE-306) in the ASUS Control Center Express (ACE) Agent, the endpoint component of ASUS's fleet-management software. An unauthenticated user on the adjacent network segment can make a direct connection to the agent and take control of the host, but only while the host has an active login session. Because no credentials are required, the attacker gains full control of the machine — the CVSS 4.0 base score of 7.7 (High) rates confidentiality, integrity, and availability impact on the vulnerable host as High, and related coverage describes unauthenticated attackers obtaining root-level access. Organizations running the ACE Agent on managed ASUS endpoints are affected, particularly where the agent is reachable from untrusted LAN segments. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.2% in 30 days), and ASUS has published a security update addressing it.

What to do: Update the ASUS Control Center Express Agent to the fixed release listed in ASUS's 'Security Update for ASUS Control Center Express Agent' advisory. Until patched, restrict access to the agent's listening interface so only trusted management segments can reach it, since any unauthenticated user on the same network segment can connect. Inventory managed ASUS endpoints for the ACE Agent and confirm whether those hosts are routinely used with active login sessions, as exploitation requires one.

Affected
ASUS Control Center Express Agent
Estimated exposure
unknown — plausibly no more than tens of thousands of managed endpoints at most — No public install counts, market-share figures, or internet-exposure scans are available for this enterprise-only management agent, which runs solely on hosts enrolled in ASUS Control Center Express and is reachable only via network…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.

Weakness
CWE-306
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access

ASUS patched CVE-2026-19397 (CVSS 7.7) in Control Center Express Agent, letting unauthenticated nearby attackers with an active session take over the host.

ASUS released version 1.7.24 of Control Center Express Agent to fix CVE-2026-19397, a CWE-306 missing-authentication flaw scored 7.7 on CVSS v4. Exploitation requires an active login session on the target and nearby network access, and agent compromise could lead to complete device takeover where the agent runs with elevated privileges. ASUS also issued a same-day advisory for Armory Crate covering ten additional CVEs.

ZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability

ZDI-26-657: ASUS Control Center Express Agent has an unauthenticated remote code execution flaw, CVE-2026-19397, rated CVSS 9.8.

The Zero Day Initiative published advisory ZDI-26-657 for ASUS Control Center Express Agent. The flaw, tracked as CVE-2026-19397, lets remote attackers execute arbitrary code without authentication. ZDI assigned a CVSS 9.8 rating. The advisory accompanies a vendor patch for affected installations.