An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA).
Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.asus.com/security-advisory/ |
|
History
Wed, 17 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Asus
Asus b460 Asus b560 Asus b660 Asus b760 Asus h410 Asus h470 Asus h510 Asus h610 Asus w480 Asus w680 Asus z590 Asus z690 Asus z790 |
|
| Vendors & Products |
Asus
Asus b460 Asus b560 Asus b660 Asus b760 Asus h410 Asus h470 Asus h510 Asus h610 Asus w480 Asus w680 Asus z590 Asus z690 Asus z790 |
Wed, 17 Dec 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information. | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ASUS
Published: 2025-12-17T04:23:51.784Z
Updated: 2025-12-17T04:23:51.784Z
Reserved: 2025-10-17T06:47:40.071Z
Link: CVE-2025-11901
No data.
Status : Received
Published: 2025-12-17T05:16:10.793
Modified: 2025-12-17T05:16:10.793
Link: CVE-2025-11901
No data.