Device Support-Lifespan Observatory

What vendors do, not what they announce.

ASUS

RT-AC66U-B1

End of support well evidenced

the vendor has said support is over

the vendor has declared end of support for this product

Sign in to be emailed when this verdict changes.
Last firmware
12 May 2026 (5 months ago)
Releases seen
8
Update rhythm
about every 3 months
Support observed
≥8 years
Vendor's promise
no support period we can evaluate
Patch latency
not measurable — its changelogs name no CVE ids

Firmware history

  1. 3.0.0.4.386_52102 12 May 2026

    Release notes — disclosure 0.43
    This model was end of its life, and its firmware, utility, website, and manual will no longer be updated. For more details, please refer to https://www.asus.com/event/network/eol-product/Security Fixes- Enhanced DNS name handling to address a potential memory issue that could occur in rare cases during name format conversion, improving system security and robustness.- Improved safeguards for execution modules to reduce the risk of substitution during certain processes.
  2. 3.0.0.4.386.48262 25 March 2022

    Cites CVE-2022-07782, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596

    Release notes — disclosure 0.91
    1. Fixed OpenSSL CVE-2022-07782. Added more security measures to block malware.3. Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.4. Fixed CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-CVE-2022-25595, CVE-2022-25596, CVE-2022-25596, 5. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.
  3. 3.0.0.4.386.46065 27 January 2022

    Release notes — disclosure 0.49
    Security- Fixed string format stacks vulnerability- Fixed cross-site-scripting vulnerability- Fixed informational vulnerability.Thanks to Howard McGreehan.-Fixed SQL injection vulnerability-Fixed json file traversal vulnerability-Fixed plc/port file traversal vulnerability-Fixed stack overflow vulnerabilityThanks to HP of Cyber Kunlun Lab-Fixed authenticated stored XSS vulnerabilityThanks to Luke Walker – SmartDCC-Fixed LPD denial of service vulnerability-Fixed cfgserver heap overflow vulnerability-Fixed cfgserver denial of service vulnerabilityThanks to TianHe from BeFun Cyber Security Lab.Added more ISP profile Digi 1 - TMDigi 2 - TIMEDigi 3 - DigiDigi 4 - CTSDigi 5 - ALLODigi 6 - SACOFAMaxis - CTSMaxis - SACOFAMaxis - TNB/ALLOFixed AiMesh guest network issues.Fixed DDNS issues where the WAN IP is IPv6Fixed UI bugs in Administration --> feedback. Fixed time zone error.
  4. 3.0.0.4.385.20490 6 May 2020

    Release notes — disclosure 0.40
    - Improved connection stability. - Optimized CPU utilization. - Fixed some UI bugs. - Fixed login bugs. - Support router certificate export. After import the certificate to the computer you will not see the warning message when login with https.Please refer to https://www.asus.com/us/support/FAQ/1034294/
  5. 3.0.0.4.385.20253 10 March 2020

    Cites CVE-2019-15126

    Release notes — disclosure 0.66
    - Fixed CVE-2019-15126 (Kr00k) vulnerability.
  6. 3.00.4.384.45149 6 December 2018

    Cites CVE-2018-14710, CVE-2018-14711, CVE-2018-14712, CVE-2018-14713, CVE-2018-14714, CVE-2018-17020, CVE-2018-17021, CVE-2018-17022

    Release notes — disclosure 0.98
    AiMesh- Improved AiMesh stability- Lyra, Lyra Mini, and Lyra Trio can be added as AiMesh node into RT-AC66U_B1 network. Please refer to https://www.asus.com/support/FAQ/1038071 for more detail.Security- Fixed CVE-2018-14710, CVE-2018-14711, CVE-2018-14712, CVE-2018-14713, CVE-2018-14714. Thanks for Rick Ramgattie's contribution.- Fixed AiCloud/ Samba account vulnerability. Thanks for Matthew Cundari's contribution.- Fixed DoS vulnerability. Thanks for Ruikai Liu's contribution.- Fixed CVE-2018-17020, CVE-2018-17021, CVE-2018-17022.- Fixed stored XSS vulnerability. Thanks for Duda Przemyslaw's contribution.- Updated OpenSSL library.Bug fixes and improvement- Improved wireless stability.- Modified “Dual Wan” user interface.- Modified “Port Forwarding” user interface.- Modified “Restore” user interface.- Fixed GUI bugs on user feedback page.- Fixed “Adaptive QoS” bugs.
  7. 3.0.0.4.384.32799 19 September 2018

    Release notes — disclosure 0.06
    Fixed WIFI stability issue.
  8. 3.0.0.4.384.32738 14 August 2018

    Release notes — disclosure 0.60
    AiMesh new features - Supported creating mesh system with new router, BlueCave. - Added Roaming block list in Advanced Settings --> Wireless. You can add devices into block list and this device will not be roamed between AiMesh nodes. - Supported ethernet onboarding. User can use ethernet cable. You can use ethernet cable to connect AiMesh router LAN port and AiMesh node WAN port first and run the adding node process to build the mesh system.Security fixes. - Fixed Reflected XSS vulnerability. - Fixed CSRF vulnerability. - Fixed command injection vulnerability. - Fixed stack buffer overflow vulnerability.Thanks for Rick Ramgattie contribution.Fixed USB hard drive over 2TB compatibility issues.Fixed Samba/FTP folder permission issues.Added USB3.0/2.0 mode switch setting in Administration --> System --> USB Settings.

Evidence

2 archived pages sit behind this record, the earliest read on 2 August 2026. Everything above was read from them, and each is kept byte for byte so it can be checked after the vendor edits the original.

Identifiers: marketing_name RT-AC66U-B1

Judged by lifecycle-1 on 29 September 2026. How these verdicts are computed.

Machine-readable: JSON · RSS