CVE-2026-19398: Medium severity ASUS FA507NV BIOS vulnerability
Published Aug 27, 2026
·Updated
An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the ' Security Update for ASUS FA507NV / FA507NU BIOS ' section on the ASUS Security Advisory for more information.
Affected Software
2 affected components
ASUS FA507NU BIOS
ASUS FA507NV BIOS
Event History
Aug 27, 2026
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires local administrator privileges on a system using the affected ASUS FA507NU or FA507NV BIOS. The attacker must be able to send a crafted software SMI request.
2
What can successful exploitation cause?
A successful oversized-length SW SMI request can cause a system crash (BSOD) or corrupt the BIOS.
3
What input triggers the vulnerable condition?
The issue is triggered by a crafted software SMI request containing an oversized length value.