Webdesk: ASUS has issued a security update for a critical vulnerability in its Control Center Enterprise platform that could allow remote attackers to gain complete control of affected systems without authentication or user interaction.
Tracked as CVE 2026 75754, the vulnerability has received a CVSS 4.0 score of 10.0, the highest possible severity rating. The flaw affects ASUS Control Center Enterprise versions up to and including 4.0.0.2.
Security researchers found that the vulnerability results from several weaknesses that can be combined to gain privileged access to a system.
One of the weaknesses involves a critical function in ASUS Control Center that does not properly require authentication. This can allow an attacker who can reach the service over a network to trigger sensitive operations.
Researchers also identified a server side request forgery weakness that can be used to make specially crafted requests and obtain the system’s encryption key. The key can then be used in combination with another weakness to enable an SSH service on TCP port 2222.
The researchers said the software also contains hard coded credentials. Together, these weaknesses can allow an attacker to access the SSH service and obtain root level control of the affected machine.
The potential impact is significant because ASUS Control Center is designed to centrally manage computers, workstations and servers. A compromised management platform could therefore provide an attacker with access beyond a single device, depending on the systems connected to it.
ASUS has urged organisations using the affected software to update to version 3.1.0.9 or later. The company has published additional information through its security advisory.
Organisations that cannot immediately install the update have been advised to reduce exposure by keeping ASUS Control Center management interfaces away from public networks and restricting traffic associated with TCP port 2222. Security teams can also check affected hosts for unexpected SSH listeners.
The vulnerability highlights the risks associated with centralised management platforms. While such systems simplify administration across large networks, a compromise of the management layer can potentially have consequences across many connected devices, making timely security updates particularly important.
ASUS, officially known as ASUSTeK Computer Inc., was founded in 1989 in Taipei, Taiwan, by four engineers from Acer: T.H. Tung, Ted Hsu, Wayne Hsieh, and M.T. Liao. It specialises in computer hardware, electronics, and peripherals, renowned for innovation, gaming products, and a global presence in PCs and related technologies.
The name “ASUS” originates from the last four letters of “Pegasus,” the winged horse in Greek mythology, symbolising aspiration and innovation. The company operates worldwide with headquarters in the Beitou District of Taipei.





