Skip to content
ASUSCVE-2026-75754

ASUS Control Center Enterprise (ACC): missing authentication

Critical10.0CVE-2026-75754 · Published Sep 4, 2026 · updated Sep 17, 2026

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.

ASUS advisory

Affected versions

PackageAffectedFixed in
Control Center Enterprise (ACC)
Product
<= through 4.0.0.2No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-306, CWE-798, CWE-918

More ASUS advisories

All ASUS
Advisory
ASUS Armoury Crate: denial of service
Medium5.7Sep 8
ASUS Armoury Crate: system information exposure
Medium5.7Sep 8
ASUS Armoury Crate: local user could free arbitrary memory
Medium5.8Sep 8
ASUS Armoury Crate: improper access control
Medium5.9Sep 8
ASUS Armoury Crate: improper access control
Low2.0Sep 8
ASUS Armoury Crate: remote user could obtain a local user's NTLM hash
Medium5.3Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.