ASUS has released security updates to address the CVE-2024-54085, an extremely serious security flaw that could allow malicious users to gain access to servers and compromise them.

The problem is found in the MegaRAC Baseboard Management Controller (BMC) software from American Megatrends International, which is used by many well-known manufacturers, such as HPE, ASUS, and ASRock.
See also: Vulnerability in Active! Mail used for attacks in Japan
The CVE-2024-54085 vulnerability can be exploited remotely and could allow malware infection, firmware tampering, or even causing serious material damage to servers.
According to analysis by security firm Eclypsium, an attacker – either local or remote – could exploit this vulnerability by gaining access to remote management interfaces (Redfish) or directly through the internal system BMC interface (Redfish). This would allow them to remotely control the server, install malware or ransomware, modify firmware, and potentially cause irreversible physical damage to the system.
Although American Megatrends International (AMI) released relevant fixes on March 11, 2025, hardware manufacturers took time to incorporate the fixes into their own products.
See also: SQL Injection vulnerabilities affect popular TP-Link routers
ASUS hasannounced that it has now released security updates for four motherboard models affected by the CVE-2024-54085 vulnerability. Users of these models are advised to update their BMC firmware to the recommended version.
- PRO WS W790E-SAGE SE – version 1.1.57 (download from here)
- PRO WS W680M-ACE SE – version 1.1.21 (download from here)
- PRO WS WRX90E-SAGE SE – version 2.1.28 (download from here)
- Pro WS WRX80E-SAGE SE WIFI – version 1.34.0 (download from here)
Due to the severity of this vulnerability and the fact that it can be exploited remotely, it is critical that you update your firmware as soon as possible.

After downloading the latest version of the BMC firmware (.ima file), you can install it via the web interface by going to the options: Maintenance > Firmware Update. There, select the file and click "Start Firmware Update". It is also recommended to enable the "Full Flash" option.
See also: North Korean hackers Kimsuky exploit RDP vulnerability
For detailed instructions on how to safely upgrade the BMC firmware and resolve potential issues, please refer to the ASUS FAQ at the corresponding link.
This issue highlights once again how critical it is to constantly monitor for vulnerabilities and promptly apply updates, especially at the firmware level.
Additional Security Measures
- Change default passwords on the BMC.
- Restrict BMC access to specific IPs (firewall rules).
- Disable Redfish or IPMI if you are not using them.
- Check for strange logs or access attempts before and after the update
Source: www.bleepingcomputer.com
