CVE-2024-0401: ASUS OVPN RCE
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0401?
CVE-2024-0401 is categorized as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-0401?
To mitigate CVE-2024-0401, update the firmware of affected ASUS routers to the latest version provided by the manufacturer.
What devices are affected by CVE-2024-0401?
Affected devices include several ASUS routers such as ExpertWiFi, RT-AX55, RT-AX58U, RT-AC67U, RT-AC68R, and RT-AX88U.
Can CVE-2024-0401 be exploited remotely?
Yes, CVE-2024-0401 can be exploited by an authenticated remote attacker through the upload of a malicious OVPN profile.
What impact does CVE-2024-0401 have on affected routers?
CVE-2024-0401 allows an attacker to execute arbitrary operating system commands on the vulnerable ASUS routers.