Description
“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the ' 
Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.
Published: 2026-08-27
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write in the SmiFlash SMM module of the device’s BIOS allows a local administrator to send a crafted software SMI request with an oversized payload. This can result in a system crash (BSOD) or in the corruption of the BIOS firmware, compromising system integrity and availability. The vulnerability does not provide remote code execution or privilege escalation beyond the local administrator role.

Affected Systems

The flaw impacts ASUS FA507NU and ASUS FA507NV models running BIOS version 318.

Risk and Exploitability

The CVSS score of 6.8 places the issue in the "medium" severity range. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation yet. Given that the attack requires local privileged access, the likelihood of exploitation is moderate and primarily limited to environments where system administrators have direct control of the hardware. As such, timely remediation through a BIOS update is strongly recommended to mitigate the risk.

Generated by OpenCVE AI on August 27, 2026 at 03:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest ASUS BIOS firmware update for the FA507NU and FA507NV models as published on the ASUS security advisory.
  • Back up the current BIOS configuration or image before installing the firmware update to enable recovery if needed.
  • After the update, restrict or monitor the use of software SMI requests, ensuring that only approved management tools are employed to reduce the risk of accidental or malicious oversized payloads.

Generated by OpenCVE AI on August 27, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 27 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in BIOS SmiFlash SMM Module Allowing Local Administrator to Trigger System Crash or BIOS Corruption on ASUS FA507NU/FA507NV

Thu, 27 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Description “unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus fa507nu
Asus fa507nv
Weaknesses CWE-787
CPEs cpe:2.3:a:asus:fa507nu:318:*:*:*:*:*:*:*
cpe:2.3:a:asus:fa507nv:318:*:*:*:*:*:*:*
Vendors & Products Asus
Asus fa507nu
Asus fa507nv
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-08-27T02:00:16.449Z

Reserved: 2026-08-10T07:25:57.688Z

Link: CVE-2026-19398

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T02:16:27.460

Modified: 2026-08-27T02:16:27.460

Link: CVE-2026-19398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T04:00:13Z

Weaknesses