CVE-2024-0401

EUVD-2024-16197
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
asusrt-ax58u
𝑥
< 3.0.0.4.388_24762
ADP
asusrt-ac67u
𝑥
< 3.0.0.4.386_51685
ADP
asusrt-ac68r
𝑥
< 3.0.0.4.386_51685
ADP
asusexpertwifi
𝑥
< 3.0.0.6.102_44544
ADP
asusrt-ax55
𝑥
< 3.0.0.4.386_52303
ADP
asusrt-ac68u
𝑥
< 3.0.0.4.386_51685
ADP
asusrt-ax86_series
𝑥
< 3.0.0.4.388_24243
ADP
asusrt-ac86u
𝑥
< 3.0.0.4.386_51925
ADP
asusrt-ac88u
𝑥
< 3.0.0.4.388_24209
ADP
asusrt-ax3000
𝑥
< 3.0.0.4.388_24762
ADP
asusrt-ac68p
𝑥
< 3.0.0.4.386_51685
ADP
asusrt-ac1900
𝑥
< 3.0.0.4.386_51685
ADP
asusrt-ac1900u
𝑥
< 3.0.0.4.386_51685
ADP
asusrt-ac2900
𝑥
< 3.0.0.4.386_51925
ADP
asuszenwifi_xt8
𝑥
< 3.0.0.4.388_24621
ADP