VYPR
patchPublished Sep 10, 2026· 1 source

Critical RCE Vulnerability in ASUS Control Center Express Agent Allows Unauthenticated Code Execution

A critical remote code execution vulnerability (CVE-2026-19397) in ASUS Control Center Express Agent allows unauthenticated attackers to execute arbitrary code on affected systems.

Zero Day Initiative (ZDI) has disclosed a severe remote code execution (RCE) vulnerability, identified as ZDI-26-657 and CVE-2026-19397, affecting ASUS Control Center Express Agent. This flaw carries a CVSS score of 9.8, underscoring its critical nature and the significant risk it poses to organizations utilizing the software.

The vulnerability resides within the Remote Desktop endpoint of the ASUS Control Center Express Agent, which typically listens on TCP port 10637. The core issue stems from a critical lack of authentication before allowing access to sensitive functionalities. This oversight enables attackers to bypass security measures and directly interact with the vulnerable component.

Exploitation of this vulnerability does not require any form of authentication, making it particularly dangerous. An unauthenticated attacker can leverage this flaw to execute arbitrary code on the target machine. The code executes with the privileges of the user currently logged into the console session of the affected system, potentially granting broad access and control.

ASUS has been notified of the vulnerability and has responded by issuing a security update to address the flaw. Users of ASUS Control Center Express Agent are strongly advised to apply the available patch as soon as possible to mitigate the risk of exploitation. Further details regarding the update and its deployment can be found on ASUS's official security advisory page.

The disclosure timeline indicates that the vulnerability was initially reported to ASUS on June 9, 2026. Following a coordinated disclosure process, ZDI published the advisory on September 10, 2026, with an update to the advisory on the same day. This timeline highlights the collaborative effort between researchers and vendors to address security issues.

The vulnerability was discovered and reported by security researcher 0x0dee, who has been credited for their work in identifying and responsibly disclosing this critical flaw. The Zero Day Initiative, a leader in vulnerability research and disclosure, plays a crucial role in facilitating the communication between researchers and vendors to ensure timely patching.

This vulnerability is significant because ASUS Control Center Express is designed for centralized IT management, often deployed in enterprise environments. A successful exploit could allow attackers to gain a foothold within a network, potentially leading to further lateral movement, data breaches, or the deployment of ransomware. The unauthenticated nature of the exploit further amplifies the threat, as it lowers the barrier to entry for malicious actors.

Organizations using ASUS Control Center Express Agent should prioritize updating their systems to the patched version. In parallel, network security teams should monitor their environments for any suspicious activity targeting the Remote Desktop endpoint on port 10637. Implementing network segmentation and access controls can also help limit the potential impact of any successful exploitation.

Synthesized by Vypr AI