CVE-2026-75754: SSRF
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is described as exploitable by an unauthorized user through an HTTP request. The request can obtain an encryption key and cause a local service to enable SSH on port 2222.
What is the resulting level of access?
After SSH is enabled, an attacker can use hard-coded credentials to obtain a root shell. This permits direct reading, writing, and deletion of ASUS Control Center data.
Could this affect systems managed through ASUS Control Center?
Yes. The described impact includes remote control of all servers, PCs, and workstations within the company that are managed through ASUS Control Center.
What should administrators consult for remediation details?
Consult the Security Update for ASUS Control Center section of the ASUS Security Advisory.