CVE-2026-4415 PUBLISHED

GIGABYTE|Gigabyte Control Center - Arbitrary File Write

Assigner: twcert
Reserved: 19.03.2026 Published: 30.03.2026 Updated: 30.03.2026

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor GIGABYTE
Product Gigabyte Control Center
Versions Default: unaffected
  • affected from 0 to 25.07.21.01 (incl.)

Solutions

Please update to version 25.12.10.01 or later.

References

Problem Types

  • CWE-23 Relative path traversal CWE

Impacts

  • CAPEC-139 Relative Path Traversal