LATEST View all updates

ASUS Control Center Express CVE-2026-19397: Check v1.7.24 and Exposure

ASUS says versions before v1.7.24 are affected; check the Agent version and network exposure.

Enterprise remote-management endpoint moving into a patched state for CVE-2026-19397

Signal Brief

  • ASUS says Control Center Express Agent versions before v1.7.24 are affected by CVE-2026-19397; update affected installations to v1.7.24 or later.
  • The flaw involves missing authentication and can allow an unauthenticated attacker who can directly reach the Agent to control a host when an active login session exists.
  • ASUS classifies the attack vector as Adjacent, while ZDI reports a TCP 10637 endpoint and uses a broader network-oriented score, so universal internet exposure should not be assumed.
  • Current reviewed evidence does not establish active exploitation of CVE-2026-19397.

ASUS Control Center Express CVE-2026-19397 affects Control Center Express Agent versions before v1.7.24. ASUS says the flaw is caused by missing authentication and can allow an unauthenticated attacker who can directly reach an affected Agent to control the host when a user has an active login session.

The immediate administrator task is straightforward: identify whether Control Center Express Agent is installed, check the exact Agent version, and update affected installations to v1.7.24 or later. The exposure question needs more care because ASUS and ZDI describe the reachable attack surface differently.

Which versions are affected by ASUS Control Center Express CVE-2026-19397?

ASUS identifies Control Center Express Agent versions before v1.7.24 as affected. The vendor-defined corrected boundary is therefore v1.7.24 or later.

An administrator should not rely on the product name alone. Verify the actual installed Agent build because an older Control Center Express deployment can remain inside the affected version range even when the application appears to be functioning normally.

What can an unauthenticated attacker do?

ASUS describes a missing-authentication condition in the Control Center Express Agent. An attacker who can directly connect to the affected Agent does not need valid application credentials and may be able to control the host when an active login session exists.

The active-login requirement matters. TPS should not describe the issue as if any powered-on machine is automatically exploitable regardless of session state.

Is CVE-2026-19397 remotely exploitable from anywhere?

That broader claim is not established by the evidence reviewed. ASUS’s CNA record classifies the attack vector as Adjacent, which indicates that reachability is more constrained than a universal internet-facing attack path.

ZDI’s coordinated disclosure describes a vulnerable Remote Desktop endpoint listening on TCP port 10637 by default and uses a more severe network-oriented scoring interpretation. These two source descriptions should be preserved rather than collapsed into a claim that every affected installation is internet-exploitable.

Why do the CVSS scores differ?

ASUS’s CNA record publishes a CVSS v4.0 score of 7.7, while ZDI uses a CVSS v3.1 score of 9.8. These are different scoring versions and source assessments, so the numbers should not be treated as directly interchangeable or as proof that one source is necessarily wrong.

For administrators, the more useful question is whether the affected Agent is present, whether it is below v1.7.24, and whether the relevant service is reachable from untrusted network segments.

Is TCP port 10637 relevant?

ZDI reports that the affected Remote Desktop endpoint listens on TCP 10637 by default. Administrators should therefore review whether that service is reachable in their environment, especially from untrusted or unnecessarily broad network segments.

This does not mean every deployment exposes TCP 10637 to the public internet. Actual reachability depends on network placement, filtering, firewall rules and how Control Center Express has been deployed.

Is CVE-2026-19397 actively exploited?

The reviewed evidence does not establish active exploitation of CVE-2026-19397. TPS is therefore not describing this vulnerability as actively exploited or as a confirmed CISA Known Exploited Vulnerabilities entry.

That evidence state can change. Administrators should treat exploitation status separately from the existence of a vendor-fixed version.

Is this the same as ASUS Control Center Enterprise CVE-2026-75754?

No. CVE-2026-19397 affects ASUS Control Center Express Agent and uses the v1.7.24 version boundary. CVE-2026-75754 concerns ASUS Control Center Enterprise, a different product and vulnerability with its own affected-version state.

What should administrators do now?

Check whether Control Center Express Agent is installed

Confirm that the endpoint or managed environment actually uses ASUS Control Center Express Agent.

Verify the installed Agent version

Treat versions before v1.7.24 as affected according to ASUS.

Update affected installations

Move affected Agents to v1.7.24 or later using current ASUS guidance.

Verify the installed version after updating

Confirm that the endpoint is actually running v1.7.24 or a later release rather than assuming the update completed.

Review network reachability

Assess whether the Agent service, including TCP 10637 where applicable, is reachable from network segments that do not need access.

Monitor for advisory changes

Recheck ASUS and coordinated disclosure guidance if exploitation, indicators of compromise or revised exposure details are published.

How can I confirm remediation?

The strongest current proof is an installed Control Center Express Agent version of v1.7.24 or later. For exposure management, administrators should also verify that outdated affected installations no longer remain in the environment and review unnecessary network reachability to the Agent service.

Because the current evidence does not establish universal internet exposure, network validation should reflect the organization’s actual architecture rather than assumptions based only on the term remote code execution.

What remains unresolved?

The public evidence does not establish how many Control Center Express installations expose the vulnerable service beyond trusted networks, whether exploitation has occurred in the wild, or why ASUS’s Adjacent-vector assessment differs from ZDI’s broader network-oriented scoring.

These uncertainties do not block the version-based remediation action: affected Agent builds below v1.7.24 should be updated.

Verification note: TPS reviewed the ASUS vendor/CNA disclosure, the coordinated ZDI disclosure information captured during research, and current vulnerability records for affected versions, authentication requirements, attack prerequisites, scoring differences and remediation state.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial guidance on ASUS Control Center Express CVE-2026-19397. ASUS confirms the affected-version boundary, but current sources differ on how broadly the vulnerable service is network-reachable, and real-world exploitation has not been established. Verify the latest ASUS and coordinated disclosure guidance before consequential security action.