cbcvebase.
CVE-2026-15030
published 2026-07-15

CVE-2026-15030: Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory…

PriorityP425medium5.6CVSS 4.0
AVLACHATNPRHUINVCHVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.11%
1.6th percentile
Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.

Affected

3 ranges
VendorProductVersion rangeFixed in
asusbusiness_manager<= v3.0.38.0
asussystem_control_interface< v1.1.40.0v1.1.40.0
asussystem_control_interface_v3< v3.1.65.0v3.1.65.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.