CVE-2025-11901: ASUS b460 Series
High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.
An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.
Affected products
- ASUS b460 Series
- ASUS b560 Series
- ASUS b660 Series
- ASUS b760 Series
- ASUS h410 Series
- ASUS h470 Series: before 3002 (fixed in 3002)
- ASUS h510 Series
- ASUS h610 Series: before 3810 (fixed in 3810)
- ASUS w480 Series
- ASUS w680 Series
- ASUS z590 Series
- ASUS z690 Series
- ASUS z790 Series
Published 2025-12-17. Last modified 2026-10-07.