CVE-2026-75754 is a critical vulnerability chain in ASUS Control Center Enterprise (ACC) combining missing authentication for a critical function, server-side request forgery, and hard-coded credentials. An unauthenticated remote attacker can use a crafted HTTP request to obtain an encryption key, which causes a local ACC service to enable an SSH listener. The attacker can then authenticate using embedded credentials and obtain a root shell on the ACC host. Versions through 4.0.0.2 are reported affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A maximum-severity, unauthenticated remote compromise vulnerability in ASUS Control Center Enterprise. Exploitation can expose an encryption key, activate an SSH listener on TCP port 2222, and use embedded credentials to gain root-level access to the ACC host and potentially control all devices managed by that ACC instance.
A CVSS 4.0 10.0 unauthenticated remote compromise vulnerability in ASUS Control Center Enterprise. The described exploit chain combines missing authentication, server-side request forgery to obtain an encryption key, automatic activation of an SSH listener on TCP/2222, and hard-coded credentials, allowing attackers to gain a root shell and potentially control all devices managed by the compromised ACC instance.
A critical ASUS Control Center vulnerability chain involving missing authentication, SSRF, and hard-coded credentials. An unauthorized attacker can retrieve an encryption key, trigger SSH activation on port 2222, authenticate with hard-coded credentials, and obtain a root shell, permitting data manipulation and remote control of managed systems.
A critical, unauthenticated remote vulnerability in ASUS Control Center that could allow a remote attacker to obtain full administrative control of an affected system.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.