CVE-2024-0401

Severity
7.2HIGH
EPSS
7.1%
top 8.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateOct 15

Description

ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages10 packages

CVEListV5asus/rt-ax55< 3.0.0.4.386_52303
CVEListV5asus/rt-ac67u< 3.0.0.4.386_51685
CVEListV5asus/rt-ac68r< 3.0.0.4.386_51685
CVEListV5asus/rt-ac68u< 3.0.0.4.386_51685
CVEListV5asus/rt-ac86u< 3.0.0.4.386_51925

🔴Vulnerability Details

2
CVEList
ASUS OVPN RCE2024-05-20
GHSA
GHSA-qxjr-363m-qwfv: ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability2024-05-20

📋Vendor Advisories

1
Oracle
Oracle Oracle Analytics Risk Matrix: Installation, BI Platform Security (OpenSSL) — CVE-2023-04012024-10-15