ZeroHour
Product

Control Center Express Agent

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

ZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability

ZDI-26-657: ASUS Control Center Express Agent has an unauthenticated remote code execution flaw, CVE-2026-19397, rated CVSS 9.8.

The Zero Day Initiative published advisory ZDI-26-657 for ASUS Control Center Express Agent. The flaw, tracked as CVE-2026-19397, lets remote attackers execute arbitrary code without authentication. ZDI assigned a CVSS 9.8 rating. The advisory accompanies a vendor patch for affected installations.

Related CVEs

  • Missing Authentication in ASUS Control Center Express Agent Allows Host Takeover
    CVE-2026-19397 is a missing-authentication flaw (CWE-306) in the ASUS Control Center Express (ACE) Agent, the endpoint component of ASUS's fleet-management software. An unauthenticated user on the adjacent network segment can make a direct connection to the agent and take control of the host, but only while the host has an active login session. Because no credentials are required, the attacker gains full control of the machine — the CVSS 4.0 base score of 7.7 (High) rates confidentiality, integrity, and availability impact on the vulnerable host as High, and related coverage describes unauthenticated attackers obtaining root-level access. Organizations running the ACE Agent on managed ASUS endpoints are affected, particularly where the agent is reachable from untrusted LAN segments. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.2% in 30 days), and ASUS has published a security update addressing it.
    · ASUS Control Center Express Agent

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.