Impact
The Aura Wallpaper Service contains an improper restriction of communication channel to intended endpoints and unauthorized control of file name or path. A local user can send crafted requests that include arbitrary file paths, bypassing the service’s built‑in path checks. This allows the attacker to read, modify or delete files on the device. The vulnerability is also known for causing disruptions to a single feature on specific models, effectively creating a denial‑of‑service scenario. The weaknesses are consistent with CWE‑73 (Path Traversal) and CWE‑923 (Improper Control of File Name or Path).
Affected Systems
The affected product is ASUS Aura Wallpaper Service. Version details are not specified but the vulnerability applies to all models that run the service as indicated by the advisory. Users should review device firmware specifications to confirm impact on their specific hardware.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability, yet the EPSS score is below 1%, suggesting a very low likelihood of exploitation in the wild at this time. The vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is local, meaning the attacker must have local access to the device. Once local access is achieved, the file manipulation can be performed immediately.
OpenCVE Enrichment