CVE-2024-0401
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
Published:May 20, 2024
Last Modified:Apr 15, 2026
EPS:May 20, 2024
EPSS Score:0.07118
CVSS Score:7.2
Affected Products
Vendor
Product
Action
Vendor
Asus
Product
4g-ac68u
Asus
4g-ac68u
Vendor
Asus
Product
Expertwifi
Asus
Expertwifi
Vendor
Asus
Product
Rt-ac1900
Asus
Rt-ac1900
Vendor
Asus
Product
Rt-ac1900u
Asus
Rt-ac1900u
Vendor
Asus
Product
Rt-ac2900
Asus
Rt-ac2900
Vendor
Asus
Product
Rt-ac67u
Asus
Rt-ac67u
Vendor
Asus
Product
Rt-ac68p
Asus
Rt-ac68p
Vendor
Asus
Product
Rt-ac68r
Asus
Rt-ac68r
Vendor
Asus
Product
Rt-ac68u
Asus
Rt-ac68u
Vendor
Asus
Product
Rt-ac86u
Asus
Rt-ac86u
Vendor
Asus
Product
Rt-ac88u
Asus
Rt-ac88u
Vendor
Asus
Product
Rt-ax3000
Asus
Rt-ax3000
Vendor
Asus
Product
Rt-ax55
Asus
Rt-ax55
Vendor
Asus
Product
Rt-ax58u
Asus
Rt-ax58u
Vendor
Asus
Product
Rt-ax86 Series
Asus
Rt-ax86 Series
Vendor
Asus
Product
Rt-ax88u
Asus
Rt-ax88u
Vendor
Asus
Product
Zenwifi Xt8
Asus
Zenwifi Xt8
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
