PT-2026-85382 · Asus · Control Center Enterprise
CVE-2026-75754
·
Published
2026-09-04
·
Updated
2026-09-08
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ASUS Control Center Enterprise versions 0 through 4.0.0.2
Description
An issue involving missing authentication for critical functions, Server-Side Request Forgery (SSRF), and the use of hard-coded credentials allows an unauthenticated network attacker to obtain an encryption key via an HTTP request. This chain of weaknesses enables the attacker to trigger a local service to activate SSH on port 2222 and authenticate using embedded credentials to obtain a root shell. Successful exploitation grants the attacker full control over the ASUS Control Center, allowing them to read, write, and delete data, as well as remotely control all managed servers, PCs, and workstations within the organization.
Recommendations
Update ASUS Control Center Enterprise to a version beyond 4.0.0.2.
Restrict the management interface to dedicated management networks and avoid public exposure.
Block unnecessary access to TCP port 2222.
Monitor for unexpected SSH activation or unexplained connections to port 2222.
Fix
RCE
Missing Authentication
Using Hardcoded Credentials
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Control Center Enterprise