Impact
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when an active login session exists. This results in full control of the host, permitting remote code execution or any actions the original user could perform. The flaw represents an authentication bypass (CWE-306).
Affected Systems
The affected product is ASUS Control Center Express Agent. No specific version information was provided in the advisory, so all releases that include the agent should be considered potentially vulnerable.
Risk and Exploitability
The CVSS score is 7.7, indicating a high severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV. The likely attack vector is a local user in proximity who can directly connect to the agent, meaning the threat requires network or physical access but is otherwise straightforward once the host has a logged‑in session. The risk is significant for environments using the agent, especially those with unmanaged local users.
OpenCVE Enrichment