CVE-2025-11901 - CVE House
Back to Database
Status published High CVE-2025-11901

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel...

Vulnerability Description

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11901

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mohamed Al-Sharifi & Nick Peterson

Affected Vendor

Affected Software

B460 series, B560 series, B660 series, B760 series, H410 series, H470 series, H510 series, H610 series, W480 series, W680 series, Z590 series, Z690 series, Z790 series
Vulnerable Versions:
before 1805, 2002, 3002, before 2402, 2803, before 3810, 4501, before 1825, 3102, before 1805, 2002, before 3002, before 3810, before 1002, 2603, 3302, before 2015, 2701, 4501, before 1825, 2102, 3102

Timeline

Official Publish: December 17th, 2025
Last Modified: December 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)