cbcvebase.
CVE-2024-0401
published 2024-05-20

CVE-2024-0401: ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary…

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.

Affected

10 ranges
VendorProductVersion rangeFixed in
asusexpertwifi< 3.0.0.6.102_445443.0.0.6.102_44544
asusrt-ac67u< 3.0.0.4.386_516853.0.0.4.386_51685
asusrt-ac68r< 3.0.0.4.386_516853.0.0.4.386_51685
asusrt-ac68u< 3.0.0.4.386_516853.0.0.4.386_51685
asusrt-ac86u< 3.0.0.4.386_519253.0.0.4.386_51925
asusrt-ax3000< 3.0.0.4.388_247623.0.0.4.388_24762
asusrt-ax55< 3.0.0.4.386_523033.0.0.4.386_52303
asusrt-ax58u< 3.0.0.4.388_247623.0.0.4.388_24762
asusrt-ax86_series< 3.0.0.4.388_242433.0.0.4.388_24243
asusrt-ax88u< 3.0.0.4.388_242093.0.0.4.388_24209