CVE-2026-19398
Received Received - Intake

Out-of-Bounds Write in ASUS FA507NU/FA507NV BIOS

Vulnerability report for CVE-2026-19398, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: ASUS

Description

“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
asus fa507nu *
asus fa507nv *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds write flaw in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS. It allows a local administrator to trigger a system crash (BSOD) or BIOS corruption by sending a crafted software SMI request with an oversized length value.

Detection Guidance

Detection requires manual inspection of BIOS versions and SMI handling. Check ASUS FA507NU/FA507NV BIOS versions against the latest security advisory. No direct commands are provided for automated detection in the given context.

Impact Analysis

An attacker with local administrator access could exploit this to crash the system or corrupt the BIOS, potentially leading to data loss or requiring a full system recovery.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a local privilege escalation issue in BIOS firmware that could lead to system instability or corruption but does not involve unauthorized data access or processing of sensitive information.

Mitigation Strategies

Update the BIOS to the latest version provided by ASUS for FA507NU and FA507NV models to address the out-of-bounds write issue in the SmiFlash SMM module.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19398. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart