PT-2024-15528 · Asus · Asus Rt-Ax58U+8
Jacob Baines
·
Published
2024-05-20
·
Updated
2024-05-22
·
CVE-2024-0401
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ASUS ExpertWiFi version (affected versions not specified)
ASUS RT-AX55 version (affected versions not specified)
ASUS RT-AX58U version (affected versions not specified)
ASUS RT-AC67U version (affected versions not specified)
ASUS RT-AC68R version (affected versions not specified)
ASUS RT-AC68U version (affected versions not specified)
ASUS RT-AX86 version (affected versions not specified)
ASUS RT-AC86U version (affected versions not specified)
ASUS RT-AX88U version (affected versions not specified)
ASUS RT-AX3000 version (affected versions not specified)
Description
The issue is a code execution vulnerability affecting ASUS routers that support custom OpenVPN profiles. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile.
Recommendations
For all affected ASUS router models, consider disabling custom OpenVPN profile support until a patch is available.
Restrict access to the OVPN profile upload feature to minimize the risk of exploitation.
Avoid using the custom OpenVPN profile feature in the affected routers until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Expertwifi
Asus Rt-Ac67U
Asus Rt-Ac68U
Asus Rt-Ac86U
Asus Rt-Ax3000
Asus Rt-Ax55
Asus Rt-Ax58U
Asus Rt-Ax86
Asus Rt-Ax88U