CVE-2026-75754
—Unauthenticated SSRF and hard-coded credentials give root in ASUS Control Center
ASUS Control Center, ASUS's centralised management platform for servers, PCs, and workstations, contains an unauthenticated vulnerability chain combining missing authentication for a critical function (CWE-306), SSRF (CWE-918), and hard-coded credentials (CWE-798), rated 10.0 critical under CVSS 4.0. An unauthorized remote attacker sends a crafted HTTP request to obtain the product's encryption key, which causes a local service to enable SSH on port 2222, and then logs in with hard-coded credentials to obtain a root shell. With root access on the Control Center host, the attacker can read, write, and delete data on the product and remotely control all servers, PCs, and workstations enrolled in the console, giving broad access to the whole managed fleet. Any organization running an affected version of ASUS Control Center is exposed, though the specific affected version ranges are only listed in the vendor's 'Security Update for ASUS Control Center' advisory section. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a 0.2% probability of exploitation within 30 days (12th percentile).
What to do: Upgrade to the fixed release identified in the 'Security Update for ASUS Control Center' section of the ASUS security advisory (specific fixed version numbers are not provided in the available data). Until patched, restrict HTTP access to the Control Center console to trusted management networks and block or monitor inbound SSH on port 2222 from untrusted sources. Check for unexpectedly enabled SSH services on port 2222 and review the console and managed endpoints for signs of unauthorized access.
| ASUS Control Center | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.
- Weakness
- CWE-306, CWE-798, CWE-918
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.