ASUS GPU Tweak III is a GPU overclocking and monitoring application for graphics cards. It works with any brand of card โ not just ASUS and ROG โ and is used to overclock, undervolt, tweak fan speeds, and monitor GPU metrics. ASUS GPU Tweak III v2.1.8.0 for Windows, and likely prior versions, contains a vulnerability chain that enables Remote Code Execution through command injection on Windows hosts running the software with the Mobile Module service component installed. The attack requires no authentication and can be triggered from the local network or potentially from a malicious website. Successful exploitation allows an attacker to execute arbitrary commands with the privileges of the user account under which the mobile plugin service runs (typically administrator).
File: GT3 mobile service.exe (Mobile Module service component; HTTP API logic in the bundled index.js)
Endpoint: POST /arrange_page_setting
Process spawning: index.js builds a reg.exe command line with attacker-controlled, unquoted JSON fields (bIsSupport, iPosIndex) and executes it through cmd.exe
Listening: tcp://0.0.0.0:5001 (all interfaces, no authentication, Access-Control-Allow-Origin: *)
When the service receives {"situation":"change_show","item":[{โฆ}]} on /arrange_page_setting, the handler (write_monitor_setting) constructs and runs:
reg add hklm\SOFTWARE\WOW6432Node\ASUS\GPUTweakIII\Mobile\Monitor /v <name> /t REG_MULTI_SZ /s, /d <bIsSupport>,<bIsShow>,<iPosIndex> /f
The fields bIsSupport and iPosIndex are inserted directly into the command string, with no quoting and no validation. Because the string is parsed by cmd.exe, shell metacharacters (&, |, >, %ENV%) are interpreted and executed. The root cause is that index.js runs the user input through a shell-interpreted command line (child_process exec / execFile with shell:true semantics) instead of passing arguments as an array.
Since the mobile service daemon listens on 0.0.0.0:5001, any machine on the network can call the API directly:
# Inject a command that writes a marker file with the output of "whoami"
curl -s "http://<victim>:5001/arrange_page_setting" \
-H "Content-Type: application/json" \
-d '{"situation":"change_show","item":[{"uDataID":"x","bIsSupport":"1 /f & whoami > C:\\pwn_lan.txt & rem x","bIsShow":1,"iPosIndex":0}]}'
The injected whoami command runs and writes its output to a marker file at C:\pwn_lan.txt, which proves arbitrary command execution.
Until ASUS ships a fix, the only dependable mitigation is to stop and disable the Mobile Module service (GT3 mobile service.exe), or to uninstall the Mobile Module component altogether, which removes the listener on TCP port 5001 entirely while leaving the core overclocking and monitoring features usable on the local machine. A Windows Defender Firewall rule that blocks inbound connections to the service only prevents other hosts on the network from reaching it; because the endpoint returns Access-Control-Allow-Origin: *, a malicious website can still make the victim's own browser issue cross-origin requests to the service over the loopback interface (127.0.0.1:5001), which host firewalls do not filter.
2026-08-30 โ Contacting ASUS regarding the security vulnerability
No reply has been received from the vendor since.
Critical Security was established in 2007 by a group of cyber security enthusiasts. Since its establishment, the company has been providing high-quality security assessments and penetration tests to various organizations, helping them identify and mitigate potential security threats.