Impact
The vulnerability in ASUS Control Center Enterprise (ACC) allows an unauthorized user to obtain the system’s encryption key via an HTTP request, which in turn enables the local service to activate SSH on port 2222. The attacker can then log in using hard‑coded credentials and acquire a root shell. With this access, the attacker can read, modify, and delete data on the Control Center and remotely control all connected servers, PCs, and workstations within the organization.
Affected Systems
The affected product is ASUS Control Center Enterprise (ACC). No specific version information is provided in the data. The product is identified by the CPE "cpe:2.3:a:asus:control_center_enterprise_acc_*:*:*:*:*:*:*:*".
Risk and Exploitability
The CVSS score is 10, indicating critical severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be a remote network exploitation via an HTTP request to the Control Center, allowing an attacker to trigger the SSRF and hard‑coded credential flaws. Once the attacker obtains the root shell, they can perform arbitrary read, write, and delete operations and exercise full remote control over the organization’s infrastructure.
OpenCVE Enrichment