# CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)

> ASUS Control Center Enterprise (ACC) contains a chain of three weaknesses - missing authentication (CWE-306), server-side request forgery (CWE-918), and hard-coded credentials (CWE-798) - that let an unauthenticated remote attacker obtain a root shell on the ACC host. Because ACC centrally manages fleets of servers, workstations, and commercial devices, a single compromise cascades into full remote control over an entire corporate IT environment. All ACC versions up to and including 4.0.0.2 are affected; ASUS fixed the chain in version 3.1.0.9 or later.

- **Published:** 2026-09-06T00:00:00Z
- **Last reviewed:** 2026-09-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2354
- **ID:** TL-2026-2354
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 2 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-75754

## Description

CVE-2026-75754 is a maximum-severity (CVSS v4.0 10.0) vulnerability chain in ASUS Control Center Enterprise (ACC), ASUS's web-based, centralized server and IT management platform. ACC is an agent/data-collector architecture delivering hardware and software monitoring (1,000+ systems), centralized BIOS flash/update management, software dispatch and task scheduling, remote desktop and power control (including BMC/IPMI), fleet inventory, and security management (role-based accounts, USB storage controls, registry protection, software blocklists) across ASUS servers, workstations, thin clients, and commercial devices.

The chain combines three distinct weaknesses. First, the software is missing authentication on a critical function (CWE-306): any unauthenticated attacker who can reach the service over HTTP can send a crafted request that causes the system to disclose its encryption key - no login and no user interaction required. Second, a server-side request forgery (CWE-918) is abused: using the leaked encryption key, the attacker triggers an internal request to a local service, which automatically enables an SSH listener on TCP port 2222, planting a hidden backdoor on the ACC host. Third, the software ships with hard-coded credentials (CWE-798): the attacker logs into the newly opened SSH service on port 2222 using the embedded fixed credentials and immediately obtains a root shell - the highest level of system access.

Impact is total on the ACC host and cascading beyond it: the attacker can read, modify, or delete any data stored in ACC (confidentiality, integrity, and availability all rated High in the CVSS v4.0 vector, including secondary-system impact), and because ACC functions as the management plane for the fleet, the root session grants remote control over every server, PC, and workstation enrolled in the ACC instance. The attack vector is network (AV:N), complexity is low (AC:L), no privileges (PR:N), and no user interaction (UI:N) is required. The CVSS v4.0 vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H.

Affected scope per the ASUS advisory is all versions of ASUS Control Center Enterprise up to and including 4.0.0.2. ASUS released a fix in version 3.1.0.9 or later (reported as an urgent security update in September 2026; the vendor's advisory notes the 3.x build line carries the patch, and ASUS recommends all users upgrade immediately via the built-in ACC Update module). The CVE record was reserved on 2026-08-18 and published on 2026-09-04; Niels Teusink of Eye Security is credited with discovery. As of this report there is no confirmed in-the-wild exploitation and no public weaponized PoC: the 30-day EPSS probability is ~0.2% and the vulnerability is not yet in the CISA KEV catalog - however the full chain is publicly documented, the attack complexity is low, and the potential for fleet-wide compromise makes immediate patching and monitoring appropriate. No attacker infrastructure (IPs, domains, hashes) has been publicly associated with this CVE, so detection focuses on the chain's behavioral fingerprints: unauthenticated HTTP requests eliciting encryption-key disclosure, unexpected SSH daemon activation, and connectivity on TCP port 2222.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter
- T1078.001 Default Accounts
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1021.004 SSH
- T1005 Data from Local System
- T1565.001 Stored Data Manipulation
- T1485 Data Destruction

## Sources

- [ASUS Product Security Advisory](https://www.asus.com/security-advisory)
- [NVD - CVE-2026-75754](https://nvd.nist.gov/vuln/detail/CVE-2026-75754)
- [ASUS Control Center Vulnerability - Cyber Security News](https://cybersecuritynews.com/asus-control-center-vulnerability/)
- [ASUS Control Center CVE-2026-75754 - SecurityOnline](https://securityonline.info/asus-control-center-cve-2026-75754/)
- [CVE-2026-75754 - Strix.ai CVE Intelligence](https://www.strix.ai/cve/CVE-2026-75754)
- [CVE-2026-75754 - IONIX Threat Center](https://www.ionix.io/threat-center/cve-2026-75754/)
- [CVE-2026-75754 - SecurityVulnerability.io](https://securityvulnerability.io/vulnerability/CVE-2026-75754)
- [CISA Known Exploited Vulnerabilities Catalog (checked - not listed as of 2026-09-06)](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2354
