Threat reportVulnerabilityTL-2026-2354

CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)

criticalACTIVE

CVE-2026-75754 (TL-2026-2354) is a critical-severity software vulnerability scored CVSS 10, first published 2026-09-06. It has no confirmed attribution, affects ASUS Control Center Enterprise (ACC), references 1 CVE (CVE-2026-75754), maps to 10 MITRE ATT&CK techniques (T1005, T1018, T1021.004), and is covered by 9 detection rules and 2 indicators of compromise.

CVSS
10/10Critical
CVEs
1Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
2Indicators of compromise

Key facts for TL-2026-2354

Threat ID
TL-2026-2354
Severity
CRITICAL
CVSS
10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
enterprise, data-center, hpc, managed-service-providers
Target regions
Worldwide
Detection rules
9
Indicators of compromise
2

Malware and tooling in CVE-2026-75754

Malware and tooling: ASUS Control Center Enterprise (ACC)

How CVE-2026-75754 works

ASUS Control Center Enterprise (ACC) contains a chain of three weaknesses - missing authentication (CWE-306), server-side request forgery (CWE-918), and hard-coded credentials (CWE-798) - that let an unauthenticated remote attacker obtain a root shell on the ACC host. Because ACC centrally manages fleets of servers, workstations, and commercial devices, a single compromise cascades into full remote control over an entire corporate IT environment. All ACC versions up to and including 4.0.0.2 are affected; ASUS fixed the chain in version 3.1.0.9 or later.

CVE-2026-75754 is a maximum-severity (CVSS v4.0 10.0) vulnerability chain in ASUS Control Center Enterprise (ACC), ASUS's web-based, centralized server and IT management platform. ACC is an agent/data-collector architecture delivering hardware and software monitoring (1,000+ systems), centralized BIOS flash/update management, software dispatch and task scheduling, remote desktop and power control (including BMC/IPMI), fleet inventory, and security management (role-based accounts, USB storage controls, registry protection, software blocklists) across ASUS servers, workstations, thin clients, and commercial devices.

The chain combines three distinct weaknesses. First, the software is missing authentication on a critical function (CWE-306): any unauthenticated attacker who can reach the service over HTTP can send a crafted request that causes the system to disclose its encryption key - no login and no user interaction required. Second, a server-side request forgery (CWE-918) is abused: using the leaked encryption key, the attacker triggers an internal request to a local service, which automatically enables an SSH listener on TCP port 2222, planting a hidden backdoor on the ACC host. Third, the software ships with hard-coded credentials (CWE-798): the attacker logs into the newly opened SSH service on port 2222 using the embedded fixed credentials and immediately obtains a root shell - the highest level of system access.

Impact is total on the ACC host and cascading beyond it: the attacker can read, modify, or delete any data stored in ACC (confidentiality, integrity, and availability all rated High in the CVSS v4.0 vector, including secondary-system impact), and because ACC functions as the management plane for the fleet, the root session grants remote control over every server, PC, and workstation enrolled in the ACC instance. The attack vector is network (AV:N), complexity is low (AC:L), no privileges (PR:N), and no user interaction (UI:N) is required. The CVSS v4.0 vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H.

Affected scope per the ASUS advisory is all versions of ASUS Control Center Enterprise up to and including 4.0.0.2. ASUS released a fix in version 3.1.0.9 or later (reported as an urgent security update in September 2026; the vendor's advisory notes the 3.x build line carries the patch, and ASUS recommends all users upgrade immediately via the built-in ACC Update module). The CVE record was reserved on 2026-08-18 and published on 2026-09-04; Niels Teusink of Eye Security is credited with discovery. As of this report there is no confirmed in-the-wild exploitation and no public weaponized PoC: the 30-day EPSS probability is ~0.2% and the vulnerability is not yet in the CISA KEV catalog - however the full chain is publicly documented, the attack complexity is low, and the potential for fleet-wide compromise makes immediate patching and monitoring appropriate. No attacker infrastructure (IPs, domains, hashes) has been publicly associated with this CVE, so detection focuses on the chain's behavioral fingerprints: unauthenticated HTTP requests eliciting encryption-key disclosure, unexpected SSH daemon activation, and connectivity on TCP port 2222.

MITRE ATT&CK techniques used in TL-2026-2354

Collection

T1005 Data from Local System

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

Lateral Movement

T1021.004 SSH

Execution

T1059 Command and Scripting Interpreter

Defense Evasion

T1078.001 Default Accounts

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Impact

T1485 Data Destruction; T1565.001 Stored Data Manipulation

Affected products and versions in CVE-2026-75754

  • ASUS — Control Center Enterprise (ACC)
    Vulnerable versions: All versions up to and including 4.0.0.2
    Fixed in: 3.1.0.9 and later

Remediation for CVE-2026-75754

Patches

  • ASUS Control Center Enterprise v3.1.0.9 or later (per ASUS Product Security Advisory, 'Security Update for ASUS Control Center', released 2026-09-04)

Immediate actions

  • Upgrade ASUS Control Center Enterprise to version 3.1.0.9 or later via the ACC built-in Update module or ASUS download center; treat the fix as urgent given the CVSS 10.0 rating
  • Block inbound and outbound TCP port 2222 at the perimeter and host firewalls until all ACC instances are confirmed patched
  • Audit every ACC host for unexpected SSH listeners (sshd) on any non-standard port, especially 2222; investigate and isolate any instance found
  • Restrict network access to ACC management interfaces: do not expose the ACC web console or its API endpoints to the internet; allowlist trusted management VLANs/source IPs only

Workarounds

  • Remove ACC management endpoints (web UI and encryption-key retrieval API) from direct internet/network exposure
  • Block TCP 2222 inbound and outbound on firewalls/ACLs as an interim safeguard
  • Monitor for unauthenticated HTTP requests targeting ACC key-disclosure endpoints and for unexpected SSH authentication events on ACC hosts

Longer-term hardening

  • Segment the server/device management plane from general corporate traffic with network access control and micro-segmentation
  • Deploy EDR/behavioral monitoring on ACC hosts and enrolled endpoints to detect anomalous SSH daemon activation, credential abuse on non-standard ports, and data-access anomalies
  • Eliminate reliance on any fixed or embedded credentials in management software; rotate all credentials reachable from ACC-managed hosts in case of prior compromise
  • Maintain an accurate inventory of all ACC deployments and versions; wire critical management-plane software into automated patching and CVE alerting

CVEs associated with CVE-2026-75754

CVE-2026-75754

Weaknesses (CWE) in CVE-2026-75754

CWE-306, CWE-918, CWE-798

Timeline of CVE-2026-75754

  • CVE-2026-75754 reserved for the ASUS Control Center Enterprise vulnerability (per CVE record metadata).
  • Niels Teusink of Eye Security credited with discovery of the vulnerability chain (per SecurityVulnerability.io CVE record); SecurityOnline and Cyber Security News publish coverage of the root-RCE chain.
  • ASUS releases ASUS Control Center version 3.1.0.9 (or later) containing the fix and strongly recommends all users update immediately.
  • CVSS v4.0 base score of 10.0 assigned (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H).
  • Vulnerability publicly disclosed: CVE-2026-75754 published and the ASUS Product Security Advisory ('Security Update for ASUS Control Center') posted.
  • No confirmed in-the-wild exploitation and no public weaponized PoC as of this date; 30-day EPSS probability ~0.2%; CISA KEV has not yet listed the CVE. Threat propagated through the Threadlinqs pipeline (TL-2026-2354).

Sources cited for CVE-2026-75754

Detection coverage for TL-2026-2354

As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2354 across Splunk SPL, Microsoft KQL and Sigma, covering 2 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
2 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats