在华硕控制中心(ASUS Control Center)中,由于关键功能缺失身份验证、存在服务器端请求伪造(SSRF)以及使用硬编码凭证,未授权的用户可以通过 HTTP 请求获取加密密钥,从而触发本地服务在 2222 端口启用 SSH。攻击者随后可以使用硬编码的凭证登录,以获取 root 权限的外壳(shell),进而直接读取、写入和删除华硕控制中心中的数据,并实现对公司内部所有服务器、PC 和工作站的远程管控。 如需了解更多信息,请参阅华硕安全公告中“ASUS 控制中心安全更新”章节。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ASUS | Control Center Enterprise (ACC) | 0 ~ 4.0.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet