{"slug":"asus-brt-ac828","display_name":"BRT-AC828","model_name":"BRT-AC828","hardware_revision":"","region_code":"","category":"router","vendor":{"slug":"asus","name":"ASUS"},"verdict":{"status":"eol_declared","label":"End of support","confidence":"high","reason":"the vendor has declared end of support for this product","algorithm_version":"lifecycle-1","computed_at":"2026-09-30T02:14:47.611578+00:00","thresholds":{"quiet_days":730,"active_max_days":365,"active_multiple":1.5,"slowing_multiple":3.0,"max_gap_dispersion":1.0,"high_confidence_releases":5,"min_releases_for_cadence":3,"never_updated_min_age_days":365}},"measurements":{"release_count":5,"first_release_date":"2018-03-28","last_release_date":"2020-04-09","days_since_last_release":2365,"median_gap_days":112.0,"cadence_multiple":21.116,"observed_support":{"days":743,"is_floor":true,"measured_from":"first_release"},"promise":{"end_date":null,"is_estimated":false,"is_floor":false,"honoured":null,"basis":"no_duration_stated"},"cve_patch_latency_days":{"median":null,"measurable":false}},"releases":[{"version":"3.0.0.4.382.70348","channel":"stable","claimed_release_date":"2020-04-09","claimed_date_precision":"day","is_vendor_dated":true,"first_observed_at":"2026-08-02T11:15:35.628116+00:00","observation_kind":"live_crawl","withdrawn_at":null,"changelog":"This model was end of its life, and its firmware, utility, website, and manual will no longer be updated. For more details, please refer to https://www.asus.com/event/network/eol-product/Note:*Facebook Wifi function is only support in firmware 3.0.0.4.380.7432_FBwifi, because Facebook has terminated the cooperation with ASUS, the subsequent firmware will not be updated. - Fixed CVE-2018-20334 - Fixed CVE-2018-20336 - Fixed null pointer issue. - Fixed DDoS vulnerability. - Fixed command injection vulnerability. - Fixed buffer overflow vulnerability. - Fixed OpenVPN related bugs. - Improved system stability.","disclosure_score":0.8,"mentions_security":true,"cve_ids":["CVE-2018-20334","CVE-2018-20336"],"download_url":null,"evidence":{"id":203580,"source_url":"https://www.asus.com/networking-iot-servers/wifi-routers/asus-wifi-routers/brt-ac828/helpdesk_bios?model2Name=BRT-AC828","fetched_at":"2026-09-29T03:06:35.664105+00:00","observed_at":"2026-09-29T03:06:35.664105+00:00","http_status":200,"content_sha256":"ed96f3b5750ad368ca1ced8f30f22c347ea592a82d29ef31dd65bfedb7725ee5","html":"//firmwarewatch.cc/evidence/203580","raw":"//firmwarewatch.cc/evidence/203580/raw"}},{"version":"3.0.0.4.380.7587","channel":"stable","claimed_release_date":"2018-12-17","claimed_date_precision":"day","is_vendor_dated":true,"first_observed_at":"2026-08-02T11:15:35.628116+00:00","observation_kind":"live_crawl","withdrawn_at":null,"changelog":"Note:*Facebook Wifi function is only support in firmware 3.0.0.4.380.7432_FBwifi, because Facebook has terminated the cooperation with ASUS, the subsequent firmware will not be updated.Bug fixed items* IPSec net-to-net peer/client connection dial fail occasionally.Modified items* Add AU/NZ ISP support in QIS and modify rule of IPTV support in wizard.* Support EULA display description editor for Captive Portal wizard.* Add IPSec PFS support.* Add IPSec log level and fix connection status display.* Fix VLAN subnet index mapping in Networkmap.* Fix “non-auth.” log in issue of Captive Portal * Rename \"Implicit beamforming\" as \"Universal Beamforming\".* Remove OpenWRT changeset from SIP ALG.* Modify “Port Forwarding” user interface.Security fixed items* Fix CVE-2018-17022 * Fix CVE-2018-17021 * Add TLS security patch* Update to OpenSSL 1.0.2p* Fix XSS vulnerability via SSID* Fix OnSec-AVS-03006004 * Fix OnSec-AVS-03006002","disclosure_score":0.8,"mentions_security":true,"cve_ids":["CVE-2018-17021","CVE-2018-17022"],"download_url":null,"evidence":{"id":203580,"source_url":"https://www.asus.com/networking-iot-servers/wifi-routers/asus-wifi-routers/brt-ac828/helpdesk_bios?model2Name=BRT-AC828","fetched_at":"2026-09-29T03:06:35.664105+00:00","observed_at":"2026-09-29T03:06:35.664105+00:00","http_status":200,"content_sha256":"ed96f3b5750ad368ca1ced8f30f22c347ea592a82d29ef31dd65bfedb7725ee5","html":"//firmwarewatch.cc/evidence/203580","raw":"//firmwarewatch.cc/evidence/203580/raw"}},{"version":"3.0.0.4.380.7526","channel":"stable","claimed_release_date":"2018-08-14","claimed_date_precision":"day","is_vendor_dated":true,"first_observed_at":"2026-08-02T11:15:35.628116+00:00","observation_kind":"live_crawl","withdrawn_at":null,"changelog":"Note:*Facebook Wifi function is only support in firmware 3.0.0.4.380.7432_FBwifi, because Facebook has terminated the cooperation with ASUS, the subsequent firmware will not be updated.New Features* [WAN] Draft VLAN support on WAN for NZ Fiber in New Zealand. Web related update:* [Policy] Privacy related modify* [Permission Management] Add a UI notice on Permission Management* [USB printer] Show USB printer function on Networkmap.* [IPSec] Modify IPSec client the remote identity requirement, when configure add Net-to-Net FAQ.* [Security] Fix security issues- Fixed Reflected XSS vulnerability.- Fixed CSRF vulnerability.- Fixed command injection vulnerability.- Fixed stack buffer overflow vulnerability.Bugfix Update:* [QIS] Redirect to internet type selection page when DHCP and PPPoE coexist.* [WAN] modify code to reboot system when value of wans_dualwan is changed from 'wan usb' to 'usb wan’.* [WAN] Reboot system when the settings of primary wan and secondary wan are exchanged. (ex. \"wan wan2\" => \"wan2 wan”) * [WAN] Remove the Auto MAC clone.* [NAT] Modify the limit of Port Forward rule* [WPS] Fix WPS default turn off issue, after restore to default on China and Taiwan H/W version * [Guest Network] Fix wifi client can't connect to hidden guest network that authentication configured on Open System.* [FreeRADIUS] Fix user authentication error when RADIUS server utility user account and password from Device Management* [Captive Portal/Free WiFi]: Modify local account and password authentication error.* [DDNS] Select public WAN IP to register DDNS server when Dual WAN load balance is enabled. * [IPSec] Fix strongswan start process error when admin account is renamed.* [IPSec] Security patch strongswan-5.2.1 to fix CVE-2018-5388, CVE-2018-10811.* [IPSec] Fix net-to-net connection issue that remote client use can't connect IPSec server with DDNS. RF related commits:* [Bandwidth] Fix HT20 enabled in legacy mode.* [TxPower] Add Tx power percentage function.* [WiFi Professional] Apply RTS threshold, DTIM period, and WME APSD to each guest networks (Virtual APs).* [WiFi Professional] Fix 11n/11ac multicast rate not be applied to main VAP.* [WiFi Professional] Add HTMIX rates","disclosure_score":0.9,"mentions_security":true,"cve_ids":["CVE-2018-10811","CVE-2018-5388"],"download_url":null,"evidence":{"id":203580,"source_url":"https://www.asus.com/networking-iot-servers/wifi-routers/asus-wifi-routers/brt-ac828/helpdesk_bios?model2Name=BRT-AC828","fetched_at":"2026-09-29T03:06:35.664105+00:00","observed_at":"2026-09-29T03:06:35.664105+00:00","http_status":200,"content_sha256":"ed96f3b5750ad368ca1ced8f30f22c347ea592a82d29ef31dd65bfedb7725ee5","html":"//firmwarewatch.cc/evidence/203580","raw":"//firmwarewatch.cc/evidence/203580/raw"}},{"version":"3.0.0.4.380.7465","channel":"stable","claimed_release_date":"2018-05-07","claimed_date_precision":"day","is_vendor_dated":true,"first_observed_at":"2026-08-02T11:15:35.628116+00:00","observation_kind":"live_crawl","withdrawn_at":null,"changelog":"Note:*Facebook Wifi function is only support in firmware 3.0.0.4.380.7432_FBwifi, because Facebook has terminated the cooperation with ASUS, the subsequent firmware will not be updated.Security fixed items[httpd] Fixed nvram_dump can dump any file and run any system command[httpd] Modify Cross-Site Scripting and single quotes naming issue for client device name on “View Client List”.[httpd] Restrict to get DHCP information before logging in[Hardware] Fixed CPU Spectre Security Vulnerability Issue.Fixed CVE-2018-8879, cleanup the bloatFixed CVE-2018-8877, CVE-2018-8878 Bug fixed items[UI] Fixed UI string translation on top status tab of main page.[httpd] fix potential crash on NULL pointer and potential buffer overrun in do_qis_default() Modified items[httpd] Modify obtain SSID and PSK method from nvram_get to nvram_char_to_ascii.[httpd] Simplify code that is used to remove unsupported channel according selected channel bandwidth.[Permission Management] Add limitations for Permission Management[Permission Management] modify user account maximum from 32 to 200.[Permission Management] modify para length to avoid parsing string crash[UI] Update descriptions of error_page.htm update descriptions of error_page.htm[UI] Updated translated string which recommended by Poland user[VLAN] Add LAN to LAN ROUTE feature for VLAN configuration","disclosure_score":0.8,"mentions_security":true,"cve_ids":["CVE-2018-8877","CVE-2018-8878","CVE-2018-8879"],"download_url":null,"evidence":{"id":203580,"source_url":"https://www.asus.com/networking-iot-servers/wifi-routers/asus-wifi-routers/brt-ac828/helpdesk_bios?model2Name=BRT-AC828","fetched_at":"2026-09-29T03:06:35.664105+00:00","observed_at":"2026-09-29T03:06:35.664105+00:00","http_status":200,"content_sha256":"ed96f3b5750ad368ca1ced8f30f22c347ea592a82d29ef31dd65bfedb7725ee5","html":"//firmwarewatch.cc/evidence/203580","raw":"//firmwarewatch.cc/evidence/203580/raw"}},{"version":"3.0.0.4.380.7432","channel":"stable","claimed_release_date":"2018-03-28","claimed_date_precision":"day","is_vendor_dated":true,"first_observed_at":"2026-08-02T11:15:35.628116+00:00","observation_kind":"live_crawl","withdrawn_at":null,"changelog":"Security fixed items * [Security] fixed LAN RCE vulnerability * dnsmasq: apply security release CVE fixes * dnsmasq: update to 2.78test2-12-gb697fbb, fix CVE-2017-13704 * Modify Smart Sync Stored XSS issue. * [Security]:fixed nvram_dump can dump any file and run any system command * [Security][CVE-2018-5721]: fixed buffer overflow in ej_update_variables when action_script includes '_wan_if' substring * [IPSec] add CVE patch for CVE-2017-11185 * [IPSec] add CVE patch for CVE-2017-9022, CVE-2017-9023 * [httpd]Fixed buffer overflow in check_xss_blacklist() Bug fixed items * Fixed IP conflicts detection code. * Fixed DUT reboot issue if number of MAC/IP binding rules greater than 30. * Main Wireless SSID not work if one or more Guest SSID configured in VLAN. * igmpproxy may listen on secondary WAN. * dnsmasq: update to 2.77-13-g69a815a, fix reserved dhcp leases * Tagged-based VLAN page can't be shown if language is FI (Suomi) or NL (Nederlands) * Sync Advanced_TagBasedVLAN_Content.asp with commit 72cf990 of ac88q branch for SQ bug#868. * Some LAN ports may not work if 802.3ad is enabled. * Can't login OpenVPN server. * Failed to connect OpenVPN server if ID has a [#] inside. * Modify IPSec UI for the IKE v1, which only support single subnet (IKE v2 support multi-subnet) * Port range of port-trigger feature doesn't work. * Wrong message if client can't connected to DUT after firmware upgrade. * Remove surge wave caused by redial from traffic graph. * Remove unsupported UI functions: Bandwidth Limiter on Guest Network of AP mode, \"Secure Your Router” button on AiProtection. * Fixed Multi-language UI issues * Fix the quotation marks will cause JS error in FR, UK * Live Update get info file : Correct equal equation of firmver value Modified items * Fix model number and serial number information of WPS. * Added new command to get blocked ACS channel. * Enable IPSec VPN switch to SW crypto and enlarge IPSec server connection number. * Modify supported symbols or special character on PSW and XAUTH of IPSec VPN * Add USB modem support: Huawei E3372. * dnsmasq: ignore localhost names from broken dhcp clients (like Samsung Smart TV) * dnsmasq: update to stable 2.78","disclosure_score":0.8,"mentions_security":true,"cve_ids":["CVE-2017-11185","CVE-2017-13704","CVE-2017-9022","CVE-2017-9023","CVE-2018-5721"],"download_url":null,"evidence":{"id":203580,"source_url":"https://www.asus.com/networking-iot-servers/wifi-routers/asus-wifi-routers/brt-ac828/helpdesk_bios?model2Name=BRT-AC828","fetched_at":"2026-09-29T03:06:35.664105+00:00","observed_at":"2026-09-29T03:06:35.664105+00:00","http_status":200,"content_sha256":"ed96f3b5750ad368ca1ced8f30f22c347ea592a82d29ef31dd65bfedb7725ee5","html":"//firmwarewatch.cc/evidence/203580","raw":"//firmwarewatch.cc/evidence/203580/raw"}}],"identifiers":[{"kind":"marketing_name","value":"BRT-AC828","normalized":"brt ac828"}],"revisions":[],"evidence":{"archived_pages":2,"first_observed_at":"2026-08-02T11:15:35.628116+00:00"},"caveats":["observed_support.days is a lower bound: it runs from the first firmware we saw, because no source here publishes launch dates.","Patch latency is not computable for this product: its changelogs name no CVE ids."],"links":{"html":"//firmwarewatch.cc/devices/asus-brt-ac828","self":"//firmwarewatch.cc/api/v1/products/asus-brt-ac828.json","vendor":"//firmwarewatch.cc/api/v1/vendors/asus.json","feed":"//firmwarewatch.cc/feeds/devices/asus-brt-ac828.xml","methodology":"//firmwarewatch.cc/api/v1/methodology.json"}}