External risk intelligence

ASUS Control Center Authentication Bypass and SSRF Vulnerability Enables Root Shell Access

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-75754

ASUS Control Center is a centralized management platform designed to monitor and control multiple servers, PCs, and workstations across a network. Such administrative and management consoles are commonly deployed as web-based interfaces and, depending on the organizational architecture, are frequently accessible via internal or external network segments to facilitate remote management.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses critical vulnerabilities in ASUS Control Center that could allow an unauthorized user to gain complete control over managed devices. The flaws enable an attacker to obtain encryption keys, activate SSH, and then use hardcoded credentials to access and manipulate data, potentially leading to widespread compromise of company servers, PCs, and workstations.

  • Issue allows unauthorized system control.
  • Affects central management systems, impacting operations.
  • Confirm relevance and exposure to your managed assets.

Attack Path

How an attacker could exploit the issue

An attacker could potentially gain unauthorized access to a company's network by exploiting vulnerabilities in ASUS Control Center. This process likely begins with the attacker identifying an exposed instance of the software, which, due to missing authentication for critical functions, allows them to make an HTTP request to obtain an encryption key. This key can then be used to enable SSH access on a specific port, allowing the attacker to log in using hardcoded credentials. Successful exploitation could grant the attacker root-level access, enabling them to read, write, or delete data, and potentially control all connected devices on the network.

  • Vulnerability exposed to the network.
  • HTTP request to obtain encryption key.
  • Full control of company servers and PCs.

Live Threat

Current exploitation, exposure, and threat context

An unauthorized user could gain access to sensitive data and gain control over ASUS Control Center managed devices. This could occur when the vulnerable service is accessible over a network, potentially allowing an attacker to obtain an encryption key and use hardcoded credentials to access a root shell. Once inside, an attacker could read, write, or delete data, and remotely control all connected servers, PCs, and workstations.

  • System data and administrative control at risk.
  • Encryption key exposed via HTTP request.
  • Full system access and remote control possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical vulnerabilities in ASUS Control Center demand immediate attention from IT infrastructure and security teams, as well as the vendor management team responsible for ASUS products. The first step is to pinpoint all instances of ASUS Control Center across the environment, confirm their network accessibility and business criticality, and identify the specific teams or individuals accountable for their management and remediation. A risk-based plan, potentially involving vendor coordination or temporary mitigations, should then be developed.

  • Infrastructure and Security teams own triage.
  • Verify network exposure and asset criticality.
  • Plan coordinated maintenance for remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ASUS Control Center?

ASUS Control Center is a centralized IT management platform used by organizations to monitor, update, and control distributed fleets of servers, workstations, and PCs from a single interface. It functions as a core administrative hub, often deployed to streamline the management of hardware assets across a company network.

What does CVE-2026-75754 mean for system security?

This CVE describes a combination of severe weaknesses, including Missing Authentication, Server-Side Request Forgery, and the use of hard-coded credentials. Together, these flaws allow an unauthorized party to bypass security controls, retrieve sensitive encryption keys, and eventually gain a root-level shell on the management server. This gives the attacker the power to read, modify, or delete any data managed by the system.

How does an attacker trigger these vulnerabilities?

An attacker triggers this by sending a specially crafted HTTP request to the ASUS Control Center, which bypasses authentication to expose an encryption key. This key allows the attacker to remotely activate an SSH service on port 2222. Simply visiting the web interface does not trigger the bug; the attacker must intentionally send these specific requests to perform the key extraction and subsequent unauthorized SSH login.

Is my environment at risk from this vulnerability?

Per Halo Surface Signal, this software is often deployed as a web interface accessible via internal or external network segments to facilitate remote management. If your instance is reachable over a network, you should treat it as a priority. You are at higher risk if the management console is exposed to the internet, though internal segments may also be accessible to anyone with network presence.

What should I do to respond to CVE-2026-75754?

Begin by identifying every instance of ASUS Control Center within your infrastructure. Confirm which devices are managed by these consoles and determine if they are accessible over your network. Coordinate with the teams responsible for these specific assets to verify their current status and prepare for security updates. Prioritize high-exposure or critical management systems as you work toward applying the vendor's official security remediations.

References