CVE-2026-4415

HIGH

GIGABYTE|Gigabyte Control Center - Arbitrary File Write

Title source: cna
STIX 2.1

Description

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.

Scores

CVSS v3 8.1
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-23 CWE-787
Status published
Products (2)
gigabyte/control_center < 25.12.10.01
GIGABYTE/Gigabyte Control Center < 25.07.21.01
Published Mar 30, 2026
Tracked Since Mar 30, 2026