7.0
HIGH CVSS 4.0
CVE-2025-11901
ASUS Motherboard Intel Chipset DMA Resource Consumption Vulnerability
Description

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.

INFO

Published Date :

Dec. 17, 2025, 5:16 a.m.

Last Modified :

June 17, 2026, 8:31 a.m.

Remotely Exploit :

No

Source :

54bf65a7-a193-42d2-b1ba-8e150d3c35e1
Affected Products

The following products are affected by CVE-2025-11901 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 4.0 HIGH 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
CVSS 4.0 HIGH 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
Solution
Update UEFI firmware to mitigate uncontrolled resource consumption and DMA risks.
  • Update UEFI firmware on affected ASUS motherboards.
  • Consult ASUS Security Advisory for details.
  • Apply relevant security patches.
Public PoC/Exploit Available at Github

CVE-2025-11901 has a 2 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2025-11901.

URL Resource
https://www.asus.com/security-advisory/
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-11901 is associated with the following CWEs:

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Updated: 6 months, 4 weeks ago
0 stars 0 fork 0 watcher
Born at : Nov. 4, 2024, 8:24 a.m. This repo has been linked 1 different CVEs too.

The last Pcileech DMA CFW guide you will ever need. Sponsored by DMAPolice.com

arbor dma emulation firmware fpga hardware pcie pcileech tlp vivado dmafw full-emu telescan chinese pcileech-fpga ufrisk pci verilog xilinx

C Tcl Roff Makefile Shell M4 Perl Assembly Linker Script Python

Updated: 1 month, 1 week ago
595 stars 122 fork 122 watcher
Born at : June 4, 2024, 4:43 a.m. This repo has been linked 4 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-11901 vulnerability anywhere in the article.

  • BleepingComputer
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock

The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks that can bypass early-boot memory protections. The securi ... Read more

Published Date: Dec 19, 2025 (8 months, 1 week ago)
  • The Hacker News
New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards

Dec 19, 2025Ravie LakshmananFirmware Security / Vulnerability Certain motherboard models from vendors like ASRock, ASUSTeK Computer, GIGABYTE, and MSI are affected by a security vulnerability that l ... Read more

Published Date: Dec 19, 2025 (8 months, 1 week ago)
  • Daily CyberSecurity
Early-Boot Attack: UEFI Flaw in ASRock, ASUS, & MSI Boards Lets Hackers Bypass OS Security via PCIe

A fundamental breakdown in how modern computers secure themselves during the boot process has been exposed, leaving systems vulnerable to physical attacks that can bypass operating system defenses ent ... Read more

Published Date: Dec 19, 2025 (8 months, 1 week ago)

The following table lists the changes that have been made to the CVE-2025-11901 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 54bf65a7-a193-42d2-b1ba-8e150d3c35e1

    Jun. 17, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'ASUS', 'product': 'B460 series', 'versions': [{'status': 'affected', 'version': 'before 1805, 2002, 3002'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'B560 series', 'versions': [{'status': 'affected', 'version': 'before 2402, 2803'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'B660 series', 'versions': [{'status': 'affected', 'version': 'before 3810, 4501'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'B760 series', 'versions': [{'status': 'affected', 'version': 'before 1825, 3102'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'H410 series', 'versions': [{'status': 'affected', 'version': 'before 1805, 2002'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'H470 series', 'versions': [{'status': 'affected', 'version': 'before 3002'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'H510 series', 'versions': [{'status': 'affected', 'version': 'before 2402, 2803'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'H610 series', 'versions': [{'status': 'affected', 'version': 'before 3810'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'W480 series', 'versions': [{'status': 'affected', 'version': 'before 1002, 2603, 3302'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'W680 series', 'versions': [{'status': 'affected', 'version': 'before 2015, 2701, 4501'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'Z590 series', 'versions': [{'status': 'affected', 'version': 'before 2402, 2803'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'Z690 series', 'versions': [{'status': 'affected', 'version': 'before 3810, 4501'}], 'defaultStatus': 'unaffected'}, {'vendor': 'ASUS', 'product': 'Z790 series', 'versions': [{'status': 'affected', 'version': 'before 1825, 2102, 3102'}], 'defaultStatus': 'unaffected'}]
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jun. 17, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2025-11901', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-12-17T21:46:16.833758Z'}
  • New CVE Received by 54bf65a7-a193-42d2-b1ba-8e150d3c35e1

    Dec. 17, 2025

    Action Type Old Value New Value
    Added Description An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.
    Added CVSS V4.0 AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-284
    Added Reference https://www.asus.com/security-advisory/
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.