CVE-2026-75754 Details
Description
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.
A vulnerability in ASUS Control Center Enterprise versions 4.0.0.2 and earlier allows unauthorized users to exploit missing authentication for critical functions, leading to server-side request forgery (SSRF) and the use of hard-coded credentials. By sending an HTTP request, an attacker can obtain an encryption key that enables a local service to activate SSH on port 2222. The attacker can then log in using the hard-coded credentials to gain root access, allowing full read, write, and delete permissions on ASUS Control Center data. This access also facilitates remote control of all servers, PCs, and workstations within the organization.
Users are advised to update to the latest version of ASUS Control Center. Instructions for updating can be found on the ASUS Security Advisory page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asus.com/security-advisory | ASUS | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | ASUS |
| CWE-798 | Use of Hard-coded Credentials | ASUS |
| CWE-918 | Server-Side Request Forgery (SSRF) | ASUS |
Affected Products
| Product | Versions |
|---|---|
| ASUS Control Center | <= 4.0.0.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | ASUS |
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | ASUS |
Volerion