Description
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable .
Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
Published: 2026-07-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Aura Wallpaper Service contains an improper restriction of communication channel to intended endpoints and unauthorized control of file name or path. A local user can send crafted requests that include arbitrary file paths, bypassing the service’s built‑in path checks. This allows the attacker to read, modify or delete files on the device. The vulnerability is also known for causing disruptions to a single feature on specific models, effectively creating a denial‑of‑service scenario. The weaknesses are consistent with CWE‑73 (Path Traversal) and CWE‑923 (Improper Control of File Name or Path).

Affected Systems

The affected product is ASUS Aura Wallpaper Service. Version details are not specified but the vulnerability applies to all models that run the service as indicated by the advisory. Users should review device firmware specifications to confirm impact on their specific hardware.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity vulnerability, yet the EPSS score is below 1%, suggesting a very low likelihood of exploitation in the wild at this time. The vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is local, meaning the attacker must have local access to the device. Once local access is achieved, the file manipulation can be performed immediately.

Generated by OpenCVE AI on August 1, 2026 at 09:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the ASUS Security Update for Aura Wallpaper Service via the firmware update utility
  • If the wallpaper feature is not required, disable or remove the service from the device to eliminate the attack surface
  • Restrict local user permissions to the Aura Wallpaper Service executable, allowing only privileged accounts to run it

Generated by OpenCVE AI on August 1, 2026 at 09:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 01 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Restriction of Communication Channel Enables Local File Manipulation in ASUS Aura Wallpaper Service

Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Improper Restriction of Communication Channel Enables Local File Manipulation in ASUS Aura Wallpaper Service

Sat, 25 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Local File Manipulation and Path Traversal in ASUS Aura Wallpaper Service

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local File Manipulation and Path Traversal in ASUS Aura Wallpaper Service

Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local File Manipulation via Aura Wallpaper Service

Thu, 16 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local File Manipulation via Aura Wallpaper Service

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus aura Wallpaper Service
Weaknesses CWE-73
CWE-923
CPEs cpe:2.3:a:asus:aura_wallpaper_service:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus aura Wallpaper Service
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N'}


Subscriptions

Asus Aura Wallpaper Service
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-15T13:12:23.878Z

Reserved: 2026-05-19T05:58:49.026Z

Link: CVE-2026-8920

cve-icon Vulnrichment

Updated: 2026-07-15T13:12:17.520Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses
  • CWE-73

    External Control of File Name or Path

  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints