Device Support-Lifespan Observatory

What vendors do, not what they announce.

ASUS

RT-AC66U B1

Gone quiet well evidenced

no firmware for long enough to stand out against its own record

337 days since the last release against a median gap of 70 (4.8x)

Sign in to be emailed when this verdict changes.
Last firmware
27 October 2025 (11 months ago)
Releases seen
25
Update rhythm
about every 2 months
Support observed
≥7 years
Vendor's promise
no support period we can evaluate
Patch latency
not measurable — its changelogs name no CVE ids

Firmware history

  1. 3.0.0.4.386_52062 27 October 2025

    Release notes — disclosure 0.42
    - Enhanced system stability.- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.- Implemented comprehensive validation and expanded command filtering in the web history API.- Fixed a privilege escalation vector in the IFTTT token exchange mechanism- Strengthened input validation and directory handling in the VPN configuration upload interface.- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
  2. 3.0.0.4.386_52048 19 August 2025

    Release notes — disclosure 0.45
    Important: After installing this firmware, we strongly recommend performing a factory-default reset to activate every new security adjustment.Security Enhancements- Password Policy Upgrade – Minimum 10 characters with at least 1 letter, 1 digit and 1 special symbol, and no consecutive identical characters; hardens defence against brute-force attacks.- HTTPS on 8443 – Management interface now served over TLS by default.- UPnP Disabled – Universal Plug and Play starts in the off state for reduced surface exposure.- AiCloud Authentication Hardening (CWE-287) – Added layered verification.- Authentication Logic Refactor – Removed redundant code paths for a lean sign-in flow.- Memory Safety Guard (CWE-476) – Introduced null-reference protections across critical services.- Enhanced IPsec Parameter Validation – The existing input checks have been hardened.- Data Exposure Mitigation (CWE-200) – Reinforced controls on sensitive pathways.
  3. 3.0.0.4.386_51733 10 March 2025

    Release notes — disclosure 0.54
    1. Fixed the UI issue in Chrome. 2. Fixed client binding issues in Mesh scenarios. 3. Enhanced input parameter handling techniques to improve data processing stability and system security. 4. Enhance system access control mechanisms.
  4. 3.0.0.4.386_51729 14 February 2025

    Release notes — disclosure 0.32
    1.Fixed the UI issue in Chrome.2.Fixed client binding issues in Mesh scenarios.
  5. 3.0.0.4.386_51722 26 November 2024

    Release notes — disclosure 0.31
    Resolved issues with customized icon functionality.
  6. 3.0.0.4.386_51720 13 November 2024

    Release notes — disclosure 0.58
    1. Strengthened input validation and data processing workflows to further protect information security.2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.3. Enhanced device security through improved buffer handling in connection features.4. Refined data handling processes, ensuring secure and accurate information management.5. Enhanced file access control mechanisms, promoting a more secure operating environment.6. Strengthened certificate protection, providing enhanced data security.
  7. 3.0.0.4.386_51685 15 April 2024

    Cites CVE-2023-35720

    Release notes — disclosure 1.00
    - Fixed command injection vulnerability.- Fixed the ARP poisoning vulnerability. Thanks to the contribution of Xin'an Zhou.- Fixed code execution in custom OVPN. Thanks to the contrubution of Jacob Baines.- Fixed the injection vulnerability in AiCloud.- Fixed stack buffer overflow in lighttpd. Special thanks to Viktor Edstrom.- Fixed CVE-2023-35720- Fixed the code execution vulnerability in AiCloud. Thanks to the contribution of chumen77.- Fixed the XSS and Self-reflected HTML injection vulnerability. Thanks to the contrubution of Redfox Cyber Security.*Please be advised that due to a security upgrade in AiMesh, we strongly recommend against downgrading to previous firmware versions, as this may lead to connection issues. Should you encounter any difficulties, resetting the AiMesh router to its default settings and re-establishing the mesh connection can resolve the problem.
  8. 3.0.0.4.386_51668 30 November 2023

    Release notes — disclosure 0.38
    1. Resolved an issue causing excessive log generation due to bwdpi issue.2. Fixed a potential issue causing higher CPU utilization.
  9. 3.0.0.4.386.51665 11 May 2023

    Cites CVE-2023-28702, CVE-2023-28703

    Release notes — disclosure 1.00
    Bug fixes and functionality modifications:-Resolved the issue with login and password changes.-Fixed the issue where Traffic Analyzer sometimes couldn't record data.Security updates:-Enabled and supported ECDSA certificates for Let's Encrypt.-Enhanced protection for credentials.-Enhanced protection for OTA firmware updates.-Fixed DoS vulnerabilities in firewall configuration pages. Thanks to Jinghe Gao's contribution.-Fixed DoS vulerabilities in httpd. Thanks to Howard McGreehan.-Fixed information disclosure vulnerability. Thanks to Junxu (Hillstone Network Security Research Institute) contribution.-Fixed CVE-2023-28702 and CVE-2023-28703. Thanks to Xingyu Xu(@tmotfl) contribution.-Fixed null pointer dereference vulnerabilities. Thanks to Chengfeng Ye, Prism Research Group - cse hkust contribution.-Fixed the cfg server vulnerability. Thanks to Swing and Wang Duo from Chaitin Security Research Lab. -Fixed the vulnerability in the logmessage function. Thanks to Swing and Wang Duo from Chaitin Security Research Lab C0ss4ck from Bytedance Wuheng Lab, Feixincheng from X1cT34m.
  10. 3.0.0.4.386.51255 2 March 2023

    Cites CVE-2018-116010, CVE-2022-263769, CVE-2022-35401, CVE-2022-38105, CVE-2022-38393

    Release notes — disclosure 0.91
    1.Fixed HTTP response splitting vulnerability.2.Fixed Samba related vulerabilities.3.Fixed cfg server security issues.4.Fixed Open redirect vulnerability.5.Fixed token authentication security issues.6.Fixed security issues on the status page.7.Fixed XSS vulnerability.8.Fixed CVE-2022-263769.Fixed CVE-2018-116010.Fixed IPv6-related bugs.11.Added a new login URL http://www.asusrouter.com to fixed the login issues.12.Optimize the AiMesh web interface13.Fixed network map UI bugs14.Fixed bugs related to Wi-Fi calling.15.Supported web history record exported.16.Fixed IPSec VPN server compatibility with Windows 10 VPN client.17.Improved AiMesh connection stability.18.Fixed IPTV issues.19. Fixed CVE-2022-35401 authentication bypass vulnerability.20. Fixed CVE-2022-38105 information disclosure vulnerability in CM process.21. Fixed CVE-2022-38393 DoS vulnerability in cfg_server.
  11. 3.0.0.4.386.49703 20 July 2022

    Cites CVE-2018-1160, CVE-2022-26376

    Release notes — disclosure 0.84
    1. Fixed CVE-2018-1160. Thanks to Steven Sroba2. Fixed CVE-2022-26376.3. Improved system stability.4. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.
  12. 3.0.0.4.386.43129 21 May 2021

    Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2020-25687

    Release notes — disclosure 0.73
    1.Fixed the FragAttack vulnerability.2.Fixed DoS vulnerability. Thanks for Tsinghua University NISL's contribution.3.Improved system stability.4.Fixed GUI bugs.5.Security Fixed: CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686
  13. 9.0.0.4.386.41994 1 February 2021

    Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25687

    Release notes — disclosure 0.74
    Security Fixed: Fixed CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686Please be noted this is a quick fix beta version for DNSmasq vulnerabilities. Refer to "Method 2: Update Manually" in https://www.asus.com/support/FAQ/1008000 to update this firmware.
  14. 3.0.0.4.386.40558 5 November 2020

    Release notes — disclosure 0.65
    New Feature1. AiMesh 2.0- System optimization: one click in AiMesh to optimize the topology- System Ethernet backhaul mode, all nodes will only connect by ethernet, all bands will be released for wireless clients.- System factory default and reboot.- Client device reconnect, make the device to offline and online again.- Client device binding to specific AP.- Guest WiFi on all Mesh nodes (all node need to upgrade to 3.0.0.4.386 firmware)- Access nodes USB application.Connection priority and Ethernet backhaul mode introduction https://www.asus.com/support/FAQ/1044184How to setup ASUS AiMesh or ZenWiFi Mesh Ethernet backhaul under different conditionshttps://www.asus.com/support/FAQ/1044151/2. New Family interface in ASUS router App. ASUS Router App for iOS must greater or equal to iOS v1.0.0.5.75 Android version greater or equal to v1.0.0.5.743. The unit of the WiFi time scheduler goes to 1 minute.4. 2.4 and 5G on the network map could be configured in the same tab.5. Captcha for login can be disabled in administration -> system.6. Printer server port can be disabled on the USB app page.7. Clients which connect to the guest network can be viewed in the network map -->view list --> interface
  15. 3.0.0.4.385.20633 14 August 2020

    Release notes — disclosure 0.30
    - Fixed RCE vulnerability.
  16. 3.0.0.4.385.20632 28 July 2020

    Release notes — disclosure 0.31
    - Fixed multi language issues
  17. 3.0.0.4.385.20630 30 June 2020

    Cites CVE-2017-15653, CVE-2020-12695

    Release notes — disclosure 0.77
    Security update - Fixed CVE-2020-12695 (CallStranger) - Fixed Reflected XSS vulnerability. - Fixed Directory traversal vulnerability. - Fixed CVE-2017-15653.The update server transport layer security was upgraded and the old protocol was removed. If your router firmware version is lower than 3.0.0.4.385.20253, please refer to the "Update Manually" section in https://www.asus.com/support/FAQ/1008000 to update the firmware.
  18. 3.0.0.4.385.20585 19 June 2020

    Release notes — disclosure 0.32
    - Fixed Let's encrypt certification renew bugs.- Improved web history page loading speed.- Fixed OpenVPN related bugs
  19. 3.0.0.4.385.20252 13 February 2020

    Release notes — disclosure 0.32
    - Fixed the firmware update problem in some special conditions.- Fixed UI bugs.
  20. 3.0.0.4.385.10002 23 December 2019

    Release notes — disclosure 0.05
    - Improved wireless stability
  21. 3.0.0.4.385.10000 26 November 2019

    Release notes — disclosure 0.31
    - Fixed firmware update issues.
  22. 3.0.0.4.384.81351 13 November 2019

    Release notes — disclosure 0.33
    - Fixed a DDoS vulnerability.- Fixed Let's Encrypt related bugs.- Fixed folder creating bugs in Samba.- Fixed dual wan failover bugs while the primary wan type is L2TP.
  23. 3.0.0.4.384.81049 4 September 2019

    Release notes — disclosure 0.48
    Security fix - Fixed a DDoS vulnerability. Thanks for Altin Thartori's contribution. Bugfix - Fixed EU 5GHz SSID disappear problems in EU model. - Fixed Network map client list issues. - Fixed block internet access problem when clients connected to AiMesh node - Fixed Samba server compatibility issue. - Fixed OpenVPN related bugs. - Fixed schedule reboot bugs. - Improved AiMesh compatibility. - Improved system stability.
  24. 3.0.0.4.384.45717 13 May 2019

    Release notes — disclosure 0.49
    - Fixed DDoS vulnerability.- Fixed AiCloud vulnerability. Thanks for Matt Cundari's contribution.- Fixed command injection vulnerability. Thanks for S1mba Lu's contribution.- Fixed buffer overflow vulnerability. Thanks for Javier Aguinaga's contribution.
  25. 3.0.0.4.384.45713 11 April 2019

    Release notes — disclosure 0.34
    Bug Fix - Fixed browser no response problem when enabled Traffic analyzer. - Fixed VLAN bug for Movistar. - Fixed the problem which causes lots of SQUASHFS error in system log.
  26. 3.0.0.4.384.45708 29 March 2019

    Cites CVE-2018-20334, CVE-2018-20336

    Release notes — disclosure 0.91
    Security Fix - Fixed CVE-2018-20334 - Fixed CVE-2018-20336 - Fixed null pointer issue. Thanks for CodeBreaker of STARLabs’ contribution. - Fixed AiCloud buffer overflow vulnerability. Thanks for Resecurity International's contribution. Bug Fix - Fixed AiMesh LAN IP issue when router using IPv6 WAN. - Fixed AIMesh connection issues. - Fixed Network Map related issues. - Fixed Download Master icon disappear issue. - Fixed LAN PC cannot find router name in My Network Places when enabling Samba service. - Fixed LAN LED not blinking problem.

Evidence

One archived page sits behind this record, the earliest read on 2 August 2026. Everything above was read from it, and each is kept byte for byte so it can be checked after the vendor edits the original.

Identifiers: marketing_name RT-AC66U B1

Judged by lifecycle-1 on 29 September 2026. How these verdicts are computed.

Machine-readable: JSON · RSS