Description
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session.
Refer to the '
Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.
Refer to the '
Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.asus.com/security-advisory |
|
History
Tue, 08 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information. | |
| First Time appeared |
Asus
Asus control Center Express Agent |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:asus:control_center_express_agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Asus
Asus control Center Express Agent |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ASUS
Published:
Updated: 2026-09-08T02:04:26.991Z
Reserved: 2026-08-10T07:25:55.486Z
Link: CVE-2026-19397
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses