Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in ASUS Control Center Exposes Systems

Critical Flaw in ASUS Control Center Exposes Systems

Posted on September 6, 2026 By CWS

ASUS has released an urgent update for its Control Center Enterprise software following the discovery of a severe vulnerability. This flaw allows remote attackers to gain complete administrative control over the system without the need for a password or user interaction.

Understanding the Vulnerability

Identified as CVE-2026-75754, this vulnerability has been rated with a CVSS 4.0 score of 10.0. This score highlights the ease of exploitation and the extensive damage potential once an attacker is inside the network.

The issue arises from a combination of three separate weaknesses. First, ASUS Control Center lacks authentication on a critical function, allowing anyone with network access to trigger sensitive operations. This is exacerbated by a server-side request forgery vulnerability, which can be exploited to access the system’s encryption key.

Exploiting the System

After obtaining the encryption key, an attacker can activate an SSH listener on TCP port 2222, effectively creating a backdoor into the machine. The most critical aspect of this flaw is the presence of hard-coded credentials within the software. These credentials enable attackers to log into the open SSH port and gain root shell access, granting them full control over the system.

Once inside, the attackers can manipulate any data within the Control Center. Given that the platform is designed to manage numerous servers, PCs, and workstations centrally, a single breach can compromise an entire corporate IT infrastructure.

Mitigation and Protection

The vulnerability affects all ASUS Control Center Enterprise versions up to 4.0.0.2. ASUS advises organizations using the software to upgrade to version 3.1.0.9 or later immediately. Detailed fix instructions are available on the ASUS Security Advisory page.

For those unable to update immediately, ASUS recommends isolating the Control Center’s management interfaces from public networks, blocking port 2222, and auditing hosts for unusual SSH listeners as temporary protective measures.

Addressing this vulnerability swiftly is crucial for maintaining security across corporate IT environments and preventing unauthorized access to sensitive data.

Cyber Security News Tags:ASUS, corporate IT security, CVE-2026-75754, Cybersecurity, encryption key, hard-coded credentials, IT management, network security, remote attack, security update, software update, SSH listener, SYSTEM access, Vulnerability

Post navigation

Previous Post: REVSTEALER Modules Disable Security to Run Crypto Miner
Next Post: MikroTik RouterOS Flaw Exploited: Urgent Patch Required

Related Posts

Hackers Leverage Built-in MacOS Protection Features to Deploy Malware Hackers Leverage Built-in MacOS Protection Features to Deploy Malware Cyber Security News
Google Chrome 144 Update Patches High-Severity V8 Vulnerability Google Chrome 144 Update Patches High-Severity V8 Vulnerability Cyber Security News
Eurofiber Data Breach – Hackers Exploited Vulnerability to Exfiltrate Users’ Data Eurofiber Data Breach – Hackers Exploited Vulnerability to Exfiltrate Users’ Data Cyber Security News
SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely Cyber Security News
Lazarus Hackers Trick Users Into Believing Their Camera or Microphone is Blocked to Deliver PyLangGhost RAT Lazarus Hackers Trick Users Into Believing Their Camera or Microphone is Blocked to Deliver PyLangGhost RAT Cyber Security News
Hackers Use Legitimate Drivers to Kill Antivirus Processes and Lower The System’s Defenses Hackers Use Legitimate Drivers to Kill Antivirus Processes and Lower The System’s Defenses Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark