RP-AC1900
End of support well evidenced
the vendor has said support is over
the vendor has declared end of support for this product
- Last firmware
- 12 May 2026 (5 months ago)
- Releases seen
- 12
- Update rhythm
- about every 7 months
- Support observed
- ≥7 years
- Vendor's promise
- no support period we can evaluate
- Patch latency
- not measurable — its changelogs name no CVE ids
Firmware history
-
3.0.0.4.386_52102 12 May 2026
Release notes — disclosure 0.43
This model was end of its life, and its firmware, utility, website, and manual will no longer be updated. For more details, please refer to https://www.asus.com/event/network/eol-product/Security Fixes- Enhanced DNS name handling to address a potential memory issue that could occur in rare cases during name format conversion, improving system security and robustness.- Improved safeguards for execution modules to reduce the risk of substitution during certain processes.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_52062 27 October 2025
Release notes — disclosure 0.42
This model was end of its life, and its firmware, utility, website, and manual will no longer be updated. For more details, please refer to https://www.asus.com/event/network/eol-product/-Enhanced system stability.-Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.-Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_51685 23 July 2024
Cites CVE-2023-35720, CVE-2024-3079, CVE-2024-3080
Release notes — disclosure 1.00
- Fixed CVE-2024-3079 and CVE-2024-3080. Thanks to the contribution of swing from Chaitin Security Research Lab.- Fixed command injection vulnerability.- Fixed the ARP poisoning vulnerability. Thanks to the contribution of Xin'an Zhou.- Fixed code execution in custom OVPN. Thanks to the contrubution of Jacob Baines.- Fixed the injection vulnerability in AiCloud.- Fixed stack buffer overflow in lighttpd. Special thanks to Viktor Edstrom.- Fixed CVE-2023-35720- Fixed the code execution vulnerability in AiCloud. Thanks to the contribution of chumen77.- Fixed the XSS and Self-reflected HTML injection vulnerability. Thanks to the contrubution of Redfox Cyber Security.*Please be advised that due to a security upgrade in AiMesh, we strongly recommend against downgrading to previous firmware versions, as this may lead to connection issues. Should you encounter any difficulties, resetting the AiMesh router to its default settings and re-establishing the mesh connection can resolve the problem.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_51668 5 December 2023
Release notes — disclosure 0.38
1. Resolved an issue causing excessive log generation due to bwdpi issue.2. Fixed a potential issue causing higher CPU utilization.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.51665 11 May 2023
Cites CVE-2023-28702, CVE-2023-28703, CVE-2023-35086, CVE-2023-35087
Release notes — disclosure 0.98
Security updates:-Enhanced protection for credentials.-Fixed DoS vulnerabilities in firewall configuration pages. Thanks to Jinghe Gao's contribution.-Fixed DoS vulerabilities in httpd. Thanks to Howard McGreehan.-Fixed information disclosure vulnerability. Thanks to Junxu (Hillstone Network Security Research Institute) contribution.-Fixed CVE-2023-28702 and CVE-2023-28703. Thanks to Xingyu Xu(@tmotfl) contribution.-Fixed null pointer dereference vulnerabilities. Thanks to Chengfeng Ye, Prism Research Group - cse hkust contribution.-Fixed the cfg server vulnerability. Thanks to Swing and Wang Duo from Chaitin Security Research Lab. -Fixed the vulnerability in the logmessage function CVE-2023-35086/ CVE-2023-35087. Thanks to Swing and Wang Duo from Chaitin Security Research Lab C0ss4ck from Bytedance Wuheng Lab, Feixincheng from X1cT34m.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.51255 2 March 2023
Cites CVE-2018-11609, CVE-2022-263768
Release notes — disclosure 0.69
1.Fixed HTTP response splitting vulnerability.2.Fixed cfg server security issues.3.Fixed Open redirect vulnerability.4.Fixed token authentication security issues.5.Fixed security issues on the status page.6.Fixed XSS vulnerability.7.Fixed CVE-2022-263768.Fixed CVE-2018-11609.Optimize the AiMesh web interface10.Improved AiMesh connection stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.49703 21 July 2022
Cites CVE-2018-1160, CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2020-25687, CVE-2021-41435, CVE-2021-41436, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-255962, CVE-2022-26376
Release notes — disclosure 0.94
1. Fixed CVE-2018-1160, CVE-2022-26376, CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2021-41435, CVE-2021-41436, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-CVE-2022-25595, CVE-2022-25596, CVE-2022-255962. Fixed httpd vulnerability3. Fixed stack overflow vulnerability4. Fixed DoS vulnerability5. Fixed Stored XSS vulnerability.6. Fixed string format stacks vulnerability7. Fixed cross-site-scripting vulnerability8. Fixed informational vulnerability.9. Fixed SQL injection vulnerability10. Fixed json file traversal vulnerability12. Fixed stack overflow vulnerability13. Fixed cfgserver heap overflow vulnerability14. Fixed cfgserver denial of service vulnerability
Archived page, fetched 29 September 2026
-
3.0.0.4.386.41634 5 May 2021
Release notes — disclosure 0.52
1. Fixed Let’s Encrypt not working properly.2. Added IPTV supports for specific region.3. Fixed parental control issues.This firmware add more security protection for configuration.4. Fixed pre-auth RCE chain through arbitrary file write, special thanks for Robert Chen's contributionIf you want to manually downgrade to previously version, please reset the router to default after downgraded.
Archived page, fetched 29 September 2026
-
3.0.0.4.385.20630 30 June 2020
Cites CVE-2017-15653, CVE-2020-12695
Release notes — disclosure 0.76
Security update - Fixed CVE-2020-12695 (CallStranger) - Fixed Reflected XSS vulnerability. - Fixed Directory traversal vulnerability. - Fixed CVE-2017-15653.The update server transport layer security was upgraded and the old protocol was removed. Please refer to the "Update Manually" section in https://www.asus.com/support/FAQ/1008000 to update the firmware.
Archived page, fetched 29 September 2026
-
3.0.0.4.385.10000 26 November 2019
Release notes — disclosure 0.31
- Fixed firmware update issues.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81351 22 November 2019
Release notes — disclosure 0.05
- Improved AiMesh stability
Archived page, fetched 29 September 2026
-
3.0.0.4.384.69640 10 June 2019
Release notes — disclosure 0.30
Initial release
Archived page, fetched 29 September 2026
Evidence
2 archived pages sit behind this record, the earliest read on 2 August 2026. Everything above was read from them, and each is kept byte for byte so it can be checked after the vendor edits the original.
Identifiers: marketing_name RP-AC1900
Judged by lifecycle-1 on 29 September 2026.
How these verdicts are computed.