ZeroHour

CVE-2026-75754

Unauthenticated SSRF and hard-coded credentials give root in ASUS Control Center

CVSS 4.0
10.0 critical
EPSS
<1%p12
Published
()
Modified
AI analysis

ASUS Control Center, ASUS's centralised management platform for servers, PCs, and workstations, contains an unauthenticated vulnerability chain combining missing authentication for a critical function (CWE-306), SSRF (CWE-918), and hard-coded credentials (CWE-798), rated 10.0 critical under CVSS 4.0. An unauthorized remote attacker sends a crafted HTTP request to obtain the product's encryption key, which causes a local service to enable SSH on port 2222, and then logs in with hard-coded credentials to obtain a root shell. With root access on the Control Center host, the attacker can read, write, and delete data on the product and remotely control all servers, PCs, and workstations enrolled in the console, giving broad access to the whole managed fleet. Any organization running an affected version of ASUS Control Center is exposed, though the specific affected version ranges are only listed in the vendor's 'Security Update for ASUS Control Center' advisory section. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a 0.2% probability of exploitation within 30 days (12th percentile).

What to do: Upgrade to the fixed release identified in the 'Security Update for ASUS Control Center' section of the ASUS security advisory (specific fixed version numbers are not provided in the available data). Until patched, restrict HTTP access to the Control Center console to trusted management networks and block or monitor inbound SSH on port 2222 from untrusted sources. Check for unexpectedly enabled SSH services on port 2222 and review the console and managed endpoints for signs of unauthorized access.

Affected
ASUS Control Center
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.

Weakness
CWE-306, CWE-798, CWE-918
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.