Junglewise Threat Intelligence

CVE-2026-19398: ASUS FA507NU and FA507NV BIOS out-of-bounds write in SmiFlash SMM

CVE-2026-19398 · Severity: info · Published 2026-08-27

Vendors: ASUS.

Executive brief

The BIOS firmware in ASUS FA507NU and FA507NV laptops contains an out-of-bounds write vulnerability in the SmiFlash SMM (System Management Mode) module. A local administrator can exploit this via a crafted SMI request to crash the system or corrupt the BIOS, disrupting business operations and potentially requiring hardware service intervention.

Technical details

The vulnerability is an out-of-bounds write in the SmiFlash SMM module triggered by a crafted software SMI (SW SMI) request containing an oversized length value. It requires local administrator privileges to exploit. An attacker with admin access can trigger a system crash (BSOD) or BIOS corruption, leading to potential data loss or inability to boot the system. The vendor has released security updates through the ASUS Security Advisory to address this issue.

Affected products

  • ASUS FA507NU BIOS
  • ASUS FA507NV BIOS

Timeline

  • 2026-08-27: disclosed

References