ASUS has disclosed a critical vulnerability, CVE-2026-75754, in its Control Center software, which allows unauthenticated attackers to gain root shell access and control managed machines. This vulnerability, which has a CVSS score of 10.0, involves missing authentication checks and hard-coded credentials, impacting all versions prior to 3.1.0.9. Users are advised to update immediately to counter potential risks. Currently, there is no confirmed exploitation in the wild.
CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE
CyberSIXT Evidence Panel
Article by CyberSIXT