CVE-2024-0401
EUVD-2024-1619720.05.2024, 17:15
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| asus | rt-ax58u | 𝑥 < 3.0.0.4.388_24762 | ADP |
| asus | rt-ac67u | 𝑥 < 3.0.0.4.386_51685 | ADP |
| asus | rt-ac68r | 𝑥 < 3.0.0.4.386_51685 | ADP |
| asus | expertwifi | 𝑥 < 3.0.0.6.102_44544 | ADP |
| asus | rt-ax55 | 𝑥 < 3.0.0.4.386_52303 | ADP |
| asus | rt-ac68u | 𝑥 < 3.0.0.4.386_51685 | ADP |
| asus | rt-ax86_series | 𝑥 < 3.0.0.4.388_24243 | ADP |
| asus | rt-ac86u | 𝑥 < 3.0.0.4.386_51925 | ADP |
| asus | rt-ac88u | 𝑥 < 3.0.0.4.388_24209 | ADP |
| asus | rt-ax3000 | 𝑥 < 3.0.0.4.388_24762 | ADP |
| asus | rt-ac68p | 𝑥 < 3.0.0.4.386_51685 | ADP |
| asus | rt-ac1900 | 𝑥 < 3.0.0.4.386_51685 | ADP |
| asus | rt-ac1900u | 𝑥 < 3.0.0.4.386_51685 | ADP |
| asus | rt-ac2900 | 𝑥 < 3.0.0.4.386_51925 | ADP |
| asus | zenwifi_xt8 | 𝑥 < 3.0.0.4.388_24621 | ADP |