go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ASUS Control Center - Broken Access Control

TVN ID TVN-202203001
CVE ID CVE-2022-26668
CVSS 7.3 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products ASUS Control Center v1.4.2.5
Description ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service.
Solution Update version to 1.4.3.2
Credit Cyku Hong (DEVCORE)
Public Date 2022-04-26
Top