Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in ASUS Control Center Exposes Systems

Critical Flaw in ASUS Control Center Exposes Systems

Posted on September 6, 2026 By CWS

ASUS has released an urgent update for its Control Center Enterprise software following the discovery of a severe vulnerability. This flaw allows remote attackers to gain complete administrative control over the system without the need for a password or user interaction.

Understanding the Vulnerability

Identified as CVE-2026-75754, this vulnerability has been rated with a CVSS 4.0 score of 10.0. This score highlights the ease of exploitation and the extensive damage potential once an attacker is inside the network.

The issue arises from a combination of three separate weaknesses. First, ASUS Control Center lacks authentication on a critical function, allowing anyone with network access to trigger sensitive operations. This is exacerbated by a server-side request forgery vulnerability, which can be exploited to access the system’s encryption key.

Exploiting the System

After obtaining the encryption key, an attacker can activate an SSH listener on TCP port 2222, effectively creating a backdoor into the machine. The most critical aspect of this flaw is the presence of hard-coded credentials within the software. These credentials enable attackers to log into the open SSH port and gain root shell access, granting them full control over the system.

Once inside, the attackers can manipulate any data within the Control Center. Given that the platform is designed to manage numerous servers, PCs, and workstations centrally, a single breach can compromise an entire corporate IT infrastructure.

Mitigation and Protection

The vulnerability affects all ASUS Control Center Enterprise versions up to 4.0.0.2. ASUS advises organizations using the software to upgrade to version 3.1.0.9 or later immediately. Detailed fix instructions are available on the ASUS Security Advisory page.

For those unable to update immediately, ASUS recommends isolating the Control Center’s management interfaces from public networks, blocking port 2222, and auditing hosts for unusual SSH listeners as temporary protective measures.

Addressing this vulnerability swiftly is crucial for maintaining security across corporate IT environments and preventing unauthorized access to sensitive data.

Cyber Security News Tags:ASUS, corporate IT security, CVE-2026-75754, Cybersecurity, encryption key, hard-coded credentials, IT management, network security, remote attack, security update, software update, SSH listener, SYSTEM access, Vulnerability

Post navigation

Previous Post: REVSTEALER Modules Disable Security to Run Crypto Miner
Next Post: MikroTik RouterOS Flaw Exploited: Urgent Patch Required

Related Posts

SonicWall Vulnerabilities Under Active Exploit Alert SonicWall Vulnerabilities Under Active Exploit Alert Cyber Security News
Urgent Updates for Jenkins Plugins Fix Critical Flaws Urgent Updates for Jenkins Plugins Fix Critical Flaws Cyber Security News
Critical MajorDoMo Vulnerability Enables Remote Code Execution Critical MajorDoMo Vulnerability Enables Remote Code Execution Cyber Security News
Threat Actors Allegedly Selling Monolock Ransomware on Dark Web Forums Threat Actors Allegedly Selling Monolock Ransomware on Dark Web Forums Cyber Security News
5 Actionable Tactics for SOC Analysts 5 Actionable Tactics for SOC Analysts Cyber Security News
INE Security Partners with Abadnet Institute for Cybersecurity Training Programs in Saudi Arabia INE Security Partners with Abadnet Institute for Cybersecurity Training Programs in Saudi Arabia Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks
  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks
  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark