RT-AC3100
End of support well evidenced
the vendor has said support is over
the vendor has declared end of support for this product
- Last firmware
- 26 February 2025 (2 years ago)
- Releases seen
- 20
- Update rhythm
- about every 3 months
- Support observed
- ≥7 years
- Vendor's promise
- no support period we can evaluate
- Patch latency
- not measurable — its changelogs name no CVE ids
Firmware history
-
3.0.0.4.386_48322 26 February 2025
Release notes — disclosure 0.40
This model was end of its life, and its firmware, utility, website, and manual will no longer be updated. For more details, please refer to https://www.asus.com/event/network/eol-product/1.Enhanced input parameter handling techniques to improve data processing stability and system security.2.Enhance system access control mechanisms.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_48313 5 December 2024
Release notes — disclosure 0.58
1. Strengthened input validation and data processing workflows to further protect information security.2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.3. Enhanced device security through improved buffer handling in connection features.4. Refined data handling processes, ensuring secure and accurate information management.5. Enhanced file access control mechanisms, promoting a more secure operating environment.6. Strengthened certificate protection, providing enhanced data security.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_48263 28 November 2023
Release notes — disclosure 0.38
1. Resolved an issue causing excessive log generation due to bwdpi issue.2. Fixed a potential issue causing higher CPU utilization.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.48260 25 March 2022
Cites CVE-2022-07782, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596
Release notes — disclosure 0.91
1. Fixed OpenSSL CVE-2022-07782. Added more security measures to block malware.3. Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.4. Fixed CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-CVE-2022-25595, CVE-2022-25596, CVE-2022-25596, 5. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.46065 25 January 2022
Release notes — disclosure 0.50
Security- Fixed string format stacks vulnerability- Fixed cross-site-scripting vulnerability- Fixed informational vulnerability.Thanks to Howard McGreehan.-Fixed SQL injection vulnerability-Fixed json file traversal vulnerability-Fixed plc/port file traversal vulnerability-Fixed stack overflow vulnerabilityThanks to HP of Cyber Kunlun Lab-Fixed authenticated stored XSS vulnerabilityThanks to Luke Walker – SmartDCC-Fixed LPD denial of service vulnerability-Fixed cfgserver heap overflow vulnerability-Fixed cfgserver denial of service vulnerabilityThanks to TianHe from BeFun Cyber Security Lab.Added more ISP profile Digi 1 - TMDigi 2 - TIMEDigi 3 - DigiDigi 4 - CTSDigi 5 - ALLODigi 6 - SACOFAMaxis - CTSMaxis - SACOFAMaxis - TNB/ALLOFixed WAN connection bug.Fixed AiProtection bug.Fixed AiMesh guest network issues.Fixed DDNS issues where the WAN IP is IPv6Fixed UI bugs in Administration --> feedback. Fixed time zone error.Fixed v6plus related issues.Improved the connection stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.43129 18 May 2021
Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2020-25687
Release notes — disclosure 0.73
1.Fixed the FragAttack vulnerability.2.Fixed DoS vulnerability. Thanks for Tsinghua University NISL's contribution.3.Improved system stability.4.Fixed GUI bugs.5.Security Fixed: CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686
Archived page, fetched 29 September 2026
-
9.0.0.4.386.41994 1 February 2021
Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25687
Release notes — disclosure 0.74
Security Fixed: Fixed CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686Please be noted this is a quick fix beta version for DNSmasq vulnerabilities. Refer to "Method 2: Update Manually" in https://www.asus.com/support/FAQ/1008000 to update this firmware.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.41700 20 January 2021
Release notes — disclosure 0.32
- Fixed Let's Encrypt not working properly.- Fixed web browsing issue when enabled parental control
Archived page, fetched 29 September 2026
-
3.0.0.4.386.41535 30 December 2020
Release notes — disclosure 0.65
1. AiMesh 2.0- System optimization: one click in AiMesh to optimize the topology- System Ethernet backhaul mode, all nodes will only connect by ethernet, all bands will be released for wireless clients.- System factory default and reboot.- Client device reconnect, make the device to offline and online again.- Client device binding to specific AP.- Guest WiFi on all Mesh nodes (all node need to upgrade to 3.0.0.4.386 firmware)- Access nodes USB application.Connection priority and Ethernet backhaul mode introductionhttps://www.asus.com/support/FAQ/1044184How to setup ASUS AiMesh or ZenWiFi Mesh Ethernet backhaul under different conditionshttps://www.asus.com/support/FAQ/1044151/2. New Family interface in ASUS router App.ASUS Router App for iOS must greater or equal to iOS v1.0.0.5.75Android version greater or equal to v1.0.0.5.743. The unit of the WiFi time scheduler goes to 1 minute.4. 2.4 and 5G on the network map could be configured in the same tab.5. Captcha for login can be disabled in administration -> system.6. Printer server port can be disabled on the USB app page.7. Clients which connect to the guest network can be viewed in the network map -->view list --> interface8. Fixed Let's encrypt issue
Archived page, fetched 29 September 2026
-
3.0.0.4.385.20631 14 August 2020
Release notes — disclosure 0.30
- Fixed RCE vulnerability.
Archived page, fetched 29 September 2026
-
3.0.0.4.385.20630 29 June 2020
Cites CVE-2017-15653, CVE-2020-12695
Release notes — disclosure 0.77
Security update - Fixed CVE-2020-12695 (CallStranger) - Fixed Reflected XSS vulnerability. - Fixed Directory traversal vulnerability. - Fixed CVE-2017-15653.The update server transport layer security was upgraded and the old protocol was removed. If your router firmware version is lower than 3.0.0.4.384.81116, please refer to the "Update Manually" section in https://www.asus.com/support/FAQ/1008000 to update the firmware
Archived page, fetched 29 September 2026
-
3.0.0.4.385.20585 17 June 2020
Release notes — disclosure 0.42
- Fixed Let's encrypt certification renew bugs. - Improved web history page loading speed. - Fixed OpenVPN related bugs - Fixed AiCloud share link bugs. - Fixed Cloud sync bugs. - Fixed offline client removing problem with ASUS router app. - In the previous version, the certificate for https login needed to be installed again after system reboot, and this version fixed this problem. - Adaptive QoS supported more apps Work-From-Home: WeChat Work®, RescueAssist, Tencent/VooV Meeting® Learn-From-Home: LinkedIn Learning®, Binkist®, Skillshare®, edX® Media Streaming: SiriusXM®, Bilibili® Indoor training: The Sufferfest®, Bkool Fitness®, TrainerRoad®, Rouvy®
Archived page, fetched 29 September 2026
-
3.0.0.4.385.20490 28 April 2020
Cites CVE-2019-15126
Release notes — disclosure 0.86
- Improved connection stability. - Optimized CPU utilization. - Fixed firmware upgrade bugs. - Fixed CVE-2019-15126 (Kr00k) vulnerability. - Fixed a DDoS vulnerability. - Fixed Let's Encrypt related bugs. - Fixed folder creating bugs in Samba. - Support router certificate export. After import the certificate to the computer you will not see the warning message when login with https. Please refer to https://www.asus.com/us/support/FAQ/1034294/ [Important notice] If router firmware is 3.0.0.4.385.20490(or newer version) and you want to downgrade to 3.0.0.4.384.81116 (or previous version), you need to reset the router after firmware changed.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81116 23 September 2019
Release notes — disclosure 0.49
Security fix - Fixed a DDoS vulnerability. Thanks for Altin Thartori's contribution. Bug fix - Fixed web control interface login problem. - Fixed Network map clist list issues. - Fixed block internet access problem when clients connected to AiMesh node - Fixed Samba server compatibility issue. - Fixed OpenVPN related bugs. - Fixed schedule reboot bugs. - Improved AiMesh compatibility. - Improved system stability. - Fixed User interface related bugs.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.45717 13 May 2019
Release notes — disclosure 0.49
- Fixed DDoS vulnerability.- Fixed AiCloud vulnerability. Thanks for Matt Cundari's contribution.- Fixed command injection vulnerability. Thanks for S1mba Lu's contribution.- Fixed buffer overflow vulnerability. Thanks for Javier Aguinaga's contribution.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.45713 11 April 2019
Release notes — disclosure 0.33
Bug Fix - Fixed browser no response problem when enabled Traffic analyzer. - Fixed VLAN bug for Movistar. - Fixed wireless mac filter input issue.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.45708 29 March 2019
Cites CVE-2018-20334, CVE-2018-20336
Release notes — disclosure 0.91
Security Fix - Fixed CVE-2018-20334 - Fixed CVE-2018-20336 - Fixed null pointer issue. Thanks for CodeBreaker of STARLabs’ contribution. - Fixed AiCloud buffer overflow vulnerability. Thanks for Resecurity International's contribution. Bug Fix - Fixed AiMesh LAN IP issue when router using IPv6 WAN. - Fixed AIMesh connection issues. - Fixed Network Map related issues. - Fixed Download Master icon disappear issue. - Fixed LAN PC cannot find router name in My Network Places when enabling Samba service. - Fixed LAN LED not blinking problem.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.45149 6 December 2018
Cites CVE-2018-14710, CVE-2018-14711, CVE-2018-14712, CVE-2018-14713, CVE-2018-14714, CVE-2018-17020, CVE-2018-17021, CVE-2018-17022
Release notes — disclosure 1.00
AiMesh- Improved AiMesh stability- Lyra, Lyra Mini, and Lyra Trio can be added as AiMesh node into RT-AC3100 network. Please refer to https://www.asus.com/support/FAQ/1038071 for more detail.Security- Fixed CVE-2018-14710, CVE-2018-14711, CVE-2018-14712, CVE-2018-14713, CVE-2018-14714. Thanks for Rick Ramgattie's contribution.- Fixed AiCloud/ Samba account vulnerability. Thanks for Matthew Cundari's contribution.- Fixed DoS vulnerability. Thanks for Ruikai Liu's contribution.- Fixed CVE-2018-17020, CVE-2018-17021, CVE-2018-17022.- Fixed stored XSS vulnerability. Thanks for Duda Przemyslaw's contribution.- Updated OpenSSL library.New Alexa skill and IFTTT actions- Add Alexa skill “ ask ASUS ROUTER to report security status”- Add Alexa skill “ ask ASUS ROUTER how many devices are online”- Add IFTTT actions : Wake on LAN- Add IFTTT actions : check new firmware available and upgrade[Note] You have to upgrade the firmware version up to 3.0.0.4.384_45149 if you want to use these new Alexa skills and IFTTT actions.Bug fixes and improvement- Improved wireless stability.- Modified “Dual Wan” user interface.- Modified “Port Forwarding” user interface.- Modified “Restore” user interface.- Fixed GUI bugs on user feedback page.- Fixed “Adaptive QoS” bugs.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.32799 19 September 2018
Release notes — disclosure 0.06
Fixed WIFI stability issue.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.32738 20 August 2018
Release notes — disclosure 0.65
AiMesh new features - Supported creating mesh system with new router, BlueCave. - Added Roaming block list in Advanced Settings --> Wireless. You can add devices into block list and this device will not be roamed between AiMesh nodes. - Supported ethernet onboarding. User can use ethernet cable. You can use ethernet cable to connect AiMesh router LAN port and AiMesh node WAN port first and run the adding node process to build the mesh system. Security fixes. - Fixed Reflected XSS vulnerability. - Fixed CSRF vulnerability. - Fixed command injection vulnerability. - Fixed stack buffer overflow vulnerability. Thanks for Rick Ramgattie contribution. Fixed USB hard drive over 2TB compatibility issues. Fixed Samba/FTP folder permission issues. Added USB3.0/2.0 mode switch setting in Administration --> System --> USB Settings.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.21045 1 June 2018
Release notes — disclosure 0.36
- Modified the EULA for DDNS, AiProtection, Adaptive QoS, Traffic Analyzer, Web history, Feedback.- Added Privacy page in Advanced settings- Fixed IPv6 bugs- Modified USB 3.0 related strings.- Increased port forwarding rules limit from 32 to 64.- Added more protection mechanism for OpenVPN account.- Fixed AiMesh bandwidth and extension channel sync issue.
Archived page, fetched 29 September 2026
Evidence
3 archived pages sit behind this record, the earliest read on 2 August 2026. Everything above was read from them, and each is kept byte for byte so it can be checked after the vendor edits the original.
Identifiers: marketing_name RT-AC3100 · openwrt_id asus_rt-ac3100
Judged by lifecycle-1 on 29 September 2026.
How these verdicts are computed.