CVE-2026-19398: Medium severity ASUS FA507NV BIOS vulnerability
“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the ' Security Update for ASUS FA507NV / FA507NU BIOS ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires local administrator privileges on a system using the affected ASUS FA507NU or FA507NV BIOS. The attacker must be able to send a crafted software SMI request.
What can successful exploitation cause?
A successful oversized-length SW SMI request can cause a system crash (BSOD) or corrupt the BIOS.
What input triggers the vulnerable condition?
The issue is triggered by a crafted software SMI request containing an oversized length value.