VDB
CVE-2025-11901
CVE-2025-11901
PUBLISHED
CVSS 7 HIGH
An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.
EPSS 0.02% · 4.1th percentile
Risk Scores
CVSS 4.0
7
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.02%
4.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ASUS | H470 series | before 3002 |
| ASUS | H610 series | before 3810 |
| ASUS | Z590 series | * |
| ASUS | B460 series | * |
| ASUS | B760 series | before 1825, 3102 |
| ASUS | W480 series | * |
| ASUS | H510 series | before 2402, 2803 |
| ASUS | H410 series | before 1805, 2002 |
| ASUS | Z790 series | before 1825, 2102, 3102 |
| ASUS | B560 series | before 2402, 2803 |
| ASUS | Z690 series | * |
| ASUS | B660 series | * |
| ASUS | W680 series | before 2015, 2701, 4501 |
Timeline
- Oct 17, 2025 CVE ID Reserved
- Dec 17, 2025 EPSS Score
- Dec 17, 2025 CVE Published
- Dec 17, 2025 CVE Updated
- Dec 19, 2025 PoC Published
- Dec 21, 2025 EPSS Score
- Dec 25, 2025 EPSS Score
- Dec 29, 2025 EPSS Score
- Jan 2, 2026 EPSS Score
- Jan 6, 2026 EPSS Score
- Jan 10, 2026 EPSS Score
- Jan 14, 2026 EPSS Score