// For flags

CVE-2024-0401

ASUS OVPN RCE

Severity Score

7.2
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.

Los enrutadores ASUS que admiten perfiles OpenVPN personalizados son afectados por una vulnerabilidad de ejecución de código. Un atacante remoto y autenticado puede ejecutar comandos arbitrarios del sistema operativo cargando un perfil OVPN manipulado. Los enrutadores afectados conocidos incluyen ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U y ASUS RT. -AX3000.

*Credits: Jacob Baines
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-01-10 CVE Reserved
  • 2024-05-20 CVE Published
  • 2024-08-01 CVE Updated
  • 2025-07-09 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
  • CAPEC-88: OS Command Injection
References (1)
URL Tag Source
https://vulncheck.com/advisories/asus-ovpn-rce Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Asus
Search vendor "Asus"
Expertwifi
Search vendor "Asus" for product "Expertwifi"
*-
Affected
Asus
Search vendor "Asus"
Rt-ac1900
Search vendor "Asus" for product "Rt-ac1900"
*-
Affected
Asus
Search vendor "Asus"
Rt-ac1900u
Search vendor "Asus" for product "Rt-ac1900u"
*-
Affected
Asus
Search vendor "Asus"
Rt-ac2900
Search vendor "Asus" for product "Rt-ac2900"
*-
Affected
Asus
Search vendor "Asus"
Rt-ac67u
Search vendor "Asus" for product "Rt-ac67u"
*-
Affected
Asus
Search vendor "Asus"
Rt-ac68p
Search vendor "Asus" for product "Rt-ac68p"
*-
Affected
Asus
Search vendor "Asus"
Rt-ac68r
Search vendor "Asus" for product "Rt-ac68r"
*-
Affected
Asus
Search vendor "Asus"
Rt-ac68u
Search vendor "Asus" for product "Rt-ac68u"
*-
Affected
Asus
Search vendor "Asus"
Rt-ac86u
Search vendor "Asus" for product "Rt-ac86u"
*-
Affected
Asus
Search vendor "Asus"
Rt-ac88u
Search vendor "Asus" for product "Rt-ac88u"
*-
Affected
Asus
Search vendor "Asus"
Rt-ax3000
Search vendor "Asus" for product "Rt-ax3000"
*-
Affected
Asus
Search vendor "Asus"
Rt-ax55
Search vendor "Asus" for product "Rt-ax55"
*-
Affected
Asus
Search vendor "Asus"
Rt-ax58u
Search vendor "Asus" for product "Rt-ax58u"
*-
Affected
Asus
Search vendor "Asus"
Rt-ax86 Series
Search vendor "Asus" for product "Rt-ax86 Series"
*-
Affected
Asus
Search vendor "Asus"
Zenwifi Xt8
Search vendor "Asus" for product "Zenwifi Xt8"
*-
Affected