Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2695 articles · 106342 vulns · 36/41 feeds (7d)
← Back to list
8.1
CVE-2026-4415EXPLOITED
gigabyte · gigabyte control center

GIGABYTE|Gigabyte Control Center - Arbitrary File Write

Description

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.

Affected Products

VendorProductVersions
gigabytegigabyte control center0, 25.07.21.01

References

  • https://www.twcert.org.tw/tw/cp-132-10803-ae014-1.html(third-party-advisory)
  • https://www.twcert.org.tw/en/cp-139-10804-689cd-2.html(third-party-advisory)

Related News (2 articles)

Tier D
BleepingComputer5h ago
GIGABYTE Control Center vulnerable to arbitrary file write flaw
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-4415 | GIGABYTE Control Center up to 25.07.21.01 path traversal (EUVD-2026-17069)
→ No new info (linked only)
CVSS 3.18.1 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-23
PublishedMar 30, 2026
Last enriched4h agov3
Tags
path traversalarbitrary file write
Trending Score55
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, patch, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (1)

NONECVE-2026-4416
GIGABYTE|Performance Library - Insecure Deserialization
Trending: 21

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Mar 30, 2026
Discovered by ZDM
Mar 30, 2026
Updated: affectedVersions, severity, activelyExploited, mitreAttack, tags
Mar 30, 2026
Actively Exploited
Mar 31, 2026
Updated: affectedVersions, tags
Mar 31, 2026

Version History

v3
Last enriched 4h ago
v3Tier D4h ago

Updated severity to CRITICAL, CVSS score to 9.2, added affected versions 25.07.21.01, and included new patch version 25.12.10.01.

affectedVersionstags
via BleepingComputer
v2Tier C1d ago

Updated severity to CRITICAL, added affected version 25.07.21.01, and included MITRE ATT&CK technique T1006.

affectedVersionsseverityactivelyExploitedmitreAttacktags
via VulDB
v11d ago

Initial creation