This is blindingly obvious and I've just noticed.
For several years now I have used the OpenVPN servers on the firmware, with very strong passwords and non-obvious usernames. I've also blocked all the other WAN-side openings, so I've thought my LAN was fairly safe.
For that reason, and being somewhat lazy and frequently up to my elbows in the fun stuff we can do, I've used a somewhat simple admin password. What I didn't realize is that the admin user is authorized for the OpenVPN servers as well. So I wasn't at all as secure as I thought.
It is perfectly clear from the server web page that this is so.
For several years now I have used the OpenVPN servers on the firmware, with very strong passwords and non-obvious usernames. I've also blocked all the other WAN-side openings, so I've thought my LAN was fairly safe.
For that reason, and being somewhat lazy and frequently up to my elbows in the fun stuff we can do, I've used a somewhat simple admin password. What I didn't realize is that the admin user is authorized for the OpenVPN servers as well. So I wasn't at all as secure as I thought.
It is perfectly clear from the server web page that this is so.