Executive brief
ASUS Control Center is a centralized management tool for controlling and monitoring ASUS servers, PCs, and workstations across enterprise networks. The product contains multiple critical security flaws—missing authentication, server-side request forgery, and hard-coded credentials—that allow an unauthenticated attacker to obtain encryption keys, enable SSH access, and gain root-level control. Once compromised, attackers can read, modify, or delete all data stored in the control center and remotely command all connected company devices, representing a complete loss of infrastructure control and data security.
Technical details
The vulnerability chain involves three distinct classes: (1) missing authentication on critical functions that expose encryption keys via HTTP requests, (2) a server-side request forgery (SSRF) condition, and (3) hard-coded credentials embedded in the product. An unauthenticated attacker on the network can exploit the SSRF and authentication bypass to retrieve the encryption key, trigger SSH enablement on port 2222, and then authenticate using the hard-coded credentials to gain an interactive root shell. This grants unrestricted read/write/delete access to all data and remote command execution across all managed systems. Patch availability and specific affected versions are referenced in the ASUS Security Advisory but not detailed in this advisory text.
Affected products
- ASUS Control Center
Timeline
- 2026-09-04: disclosed