---
id: CVE-2026-19398
title: "An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local\_ administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value…"
summary: "An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local\_ administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value…"
severity: medium
cvss: 6.8
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-787
vendor: ASUS
product: FA507NV
affected:
  - FA507NV 318
  - FA507NU 318
published: '2026-08-27'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T04:17:56.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19398'
references:
  - url: 'https://www.asus.com/security-advisory'
    label: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-27T14:50:25.695502Z'
cvssSource: cna
ingestedAt: '2026-09-14T14:14:42.827Z'
epss: 0.00112
epssPercentile: 0.01243
---

## Overview

An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the ' 
Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
