CVE-2022-26669

HIGH

ASUS Control Center - SQL Injection

Title source: llm
STIX 2.1

Description

ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-6056-b0d90-1.html

Scores

CVSS v3 8.8
EPSS 0.0031
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
asus/control_center 1.4.2.5
Published Jun 20, 2022
Tracked Since Feb 18, 2026