VDB

CVE-2025-11901

CVE-2025-11901 PUBLISHED CVSS 7 HIGH

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.

EPSS 0.02% · 4.1th percentile

Risk Scores

CVSS 4.0
7
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.02%
4.1th percentile

Affected Products

VendorProductVersions
ASUSH470 seriesbefore 3002
ASUSH610 seriesbefore 3810
ASUSZ590 series*
ASUSB460 series*
ASUSB760 seriesbefore 1825, 3102
ASUSW480 series*
ASUSH510 seriesbefore 2402, 2803
ASUSH410 seriesbefore 1805, 2002
ASUSZ790 seriesbefore 1825, 2102, 3102
ASUSB560 seriesbefore 2402, 2803
ASUSZ690 series*
ASUSB660 series*
ASUSW680 seriesbefore 2015, 2701, 4501

Timeline

  • Oct 17, 2025 CVE ID Reserved
  • Dec 17, 2025 EPSS Score
  • Dec 17, 2025 CVE Published
  • Dec 17, 2025 CVE Updated
  • Dec 19, 2025 PoC Published
  • Dec 21, 2025 EPSS Score
  • Dec 25, 2025 EPSS Score
  • Dec 29, 2025 EPSS Score
  • Jan 2, 2026 EPSS Score
  • Jan 6, 2026 EPSS Score
  • Jan 10, 2026 EPSS Score
  • Jan 14, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›