CVE-2025-11901
An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.
Published:Dec 17, 2025
Last Modified:Apr 15, 2026
EPS:Dec 17, 2025
EPSS Score:0.00027
CVSS Score:7
Affected Products
Vendor
Product
Action
Vendor
Asus
Product
B460
Asus
B460
Vendor
Asus
Product
B560
Asus
B560
Vendor
Asus
Product
B660
Asus
B660
Vendor
Asus
Product
B760
Asus
B760
Vendor
Asus
Product
H410
Asus
H410
Vendor
Asus
Product
H470
Asus
H470
Vendor
Asus
Product
H510
Asus
H510
Vendor
Asus
Product
H610
Asus
H610
Vendor
Asus
Product
W480
Asus
W480
Vendor
Asus
Product
W680
Asus
W680
Vendor
Asus
Product
Z590
Asus
Z590
Vendor
Asus
Product
Z690
Asus
Z690
Vendor
Asus
Product
Z790
Asus
Z790
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
