Executive brief
ASUS Control Center Express Agent is a system management utility that runs on ASUS computers. The agent lacks authentication checks on a critical administrative function, allowing a nearby attacker with network access to the agent to take full control of the host system when a user is logged in.
Technical details
This vulnerability is an authentication bypass in the ASUS Control Center Express Agent service. A critical administrative function fails to validate the caller's identity before executing privileged operations. An attacker with adjacent network access (same LAN or direct connection) can send requests directly to the agent service without credentials to execute arbitrary administrative commands on the host. The vulnerability requires an active user login session on the target system to succeed. ASUS has released security updates to address this issue via their security advisory page.
Affected products
- ASUS Control Center Express Agent <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory