PT-2026-85382 · Asus · Control Center Enterprise

CVE-2026-75754

·

Published

2026-09-04

·

Updated

2026-09-08

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ASUS Control Center Enterprise versions 0 through 4.0.0.2
Description An issue involving missing authentication for critical functions, Server-Side Request Forgery (SSRF), and the use of hard-coded credentials allows an unauthenticated network attacker to obtain an encryption key via an HTTP request. This chain of weaknesses enables the attacker to trigger a local service to activate SSH on port 2222 and authenticate using embedded credentials to obtain a root shell. Successful exploitation grants the attacker full control over the ASUS Control Center, allowing them to read, write, and delete data, as well as remotely control all managed servers, PCs, and workstations within the organization.
Recommendations Update ASUS Control Center Enterprise to a version beyond 4.0.0.2. Restrict the management interface to dedicated management networks and avoid public exposure. Block unnecessary access to TCP port 2222. Monitor for unexpected SSH activation or unexplained connections to port 2222.

Fix

RCE

Missing Authentication

Using Hardcoded Credentials

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75754

Affected Products

Control Center Enterprise