ASUS has released an urgent update for its Control Center Enterprise software following the discovery of a severe vulnerability. This flaw allows remote attackers to gain complete administrative control over the system without the need for a password or user interaction.
Understanding the Vulnerability
Identified as CVE-2026-75754, this vulnerability has been rated with a CVSS 4.0 score of 10.0. This score highlights the ease of exploitation and the extensive damage potential once an attacker is inside the network.
The issue arises from a combination of three separate weaknesses. First, ASUS Control Center lacks authentication on a critical function, allowing anyone with network access to trigger sensitive operations. This is exacerbated by a server-side request forgery vulnerability, which can be exploited to access the system’s encryption key.
Exploiting the System
After obtaining the encryption key, an attacker can activate an SSH listener on TCP port 2222, effectively creating a backdoor into the machine. The most critical aspect of this flaw is the presence of hard-coded credentials within the software. These credentials enable attackers to log into the open SSH port and gain root shell access, granting them full control over the system.
Once inside, the attackers can manipulate any data within the Control Center. Given that the platform is designed to manage numerous servers, PCs, and workstations centrally, a single breach can compromise an entire corporate IT infrastructure.
Mitigation and Protection
The vulnerability affects all ASUS Control Center Enterprise versions up to 4.0.0.2. ASUS advises organizations using the software to upgrade to version 3.1.0.9 or later immediately. Detailed fix instructions are available on the ASUS Security Advisory page.
For those unable to update immediately, ASUS recommends isolating the Control Center’s management interfaces from public networks, blocking port 2222, and auditing hosts for unusual SSH listeners as temporary protective measures.
Addressing this vulnerability swiftly is crucial for maintaining security across corporate IT environments and preventing unauthorized access to sensitive data.
