ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability

highAdvisoryimportance 35CVE-2026-19397
AI summary · glm-5.3-flash

ZDI-26-657: ASUS Control Center Express Agent has an unauthenticated remote code execution flaw, CVE-2026-19397, rated CVSS 9.8.

The Zero Day Initiative published advisory ZDI-26-657 for ASUS Control Center Express Agent. The flaw, tracked as CVE-2026-19397, lets remote attackers execute arbitrary code without authentication. ZDI assigned a CVSS 9.8 rating. The advisory accompanies a vendor patch for affected installations.

  • Unauthenticated remote code execution in ASUS Control Center Express Agent
  • Tracked as CVE-2026-19397 with CVSS 9.8
  • Disclosure coordinated by the Zero Day Initiative
  • Vendor patch available for affected installations

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-19397
Missing Authentication in ASUS Control Center Express Agent Allows Host Takeover

CVE-2026-19397 is a missing-authentication flaw (CWE-306) in the ASUS Control Center Express (ACE) Agent, the endpoint component of ASUS's fleet-management software. An unauthenticated user on the adjacent network segment can make a direct connection to the agent and take control of the host, but only while the host has an active login session. Because no credentials are required, the attacker gains full control of the machine — the CVSS 4.0 base score of 7.7 (High) rates confidentiality, integrity, and availability impact on the vulnerable host as High, and related coverage describes unauthenticated attackers obtaining root-level access. Organizations running the ACE Agent on managed ASUS endpoints are affected, particularly where the agent is reachable from untrusted LAN segments. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.2% in 30 days), and ASUS has published a security update addressing it.

Do: Update the ASUS Control Center Express Agent to the fixed release listed in ASUS's 'Security Update for ASUS Control Center Express Agent' advisory. Until patched, restrict access to the agent's listening interface so only trusted management segments can reach it, since any unauthenticated user on the same network segment can connect. Inventory managed ASUS endpoints for the ACE Agent and confirm whether those hosts are routinely used with active login sessions, as exploitation requires one.

7.7<1%
  • ASUS Control Center Express Agent
unknown
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of ASUS Control Center Express Agent. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19397.

This source does not provide full text. Read it at zerodayinitiative.com.