RT-AC86U
End of support well evidenced
the vendor has said support is over
the vendor has declared end of support for this product
- Last firmware
- 7 May 2026 (5 months ago)
- Releases seen
- 29
- Update rhythm
- about every 3 months
- Support observed
- ≥8 years
- Vendor's promise
- no support period we can evaluate
- Patch latency
- not measurable — its changelogs name no CVE ids
Firmware history
-
3.0.0.4.386_52334 7 May 2026
Release notes — disclosure 0.43
This model was end of its life, and its firmware, utility, website, and manual will no longer be updated. For more details, please refer to https://www.asus.com/event/network/eol-product/.Security Fixes- Enhanced DNS name handling to address a potential memory issue that could occur in rare cases during name format conversion, improving system security and robustness.- Improved safeguards for execution modules to reduce the risk of substitution during certain processes.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_52294 28 October 2025
Release notes — disclosure 0.42
- Enhanced system stability.- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.- Implemented comprehensive validation and expanded command filtering in the web history API.- Fixed a privilege escalation vector in the IFTTT token exchange mechanism- Strengthened input validation and directory handling in the VPN configuration upload interface.- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_51967 25 March 2025
Release notes — disclosure 0.49
1. Fixed the UI issue in Chrome.2. Fixed client binding issues in Mesh scenarios.3. Enhanced input parameter handling techniques to improve data processing stability and system security.4. Enhance system access control mechanisms.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_51955 8 November 2024
Release notes — disclosure 0.58
1. Strengthened input validation and data processing workflows to further protect information security.2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.3. Enhanced device security through improved buffer handling in connection features.4. Refined data handling processes, ensuring secure and accurate information management.5. Enhanced file access control mechanisms, promoting a more secure operating environment.6. Strengthened certificate protection, providing enhanced data security.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_51925 29 March 2024
Cites CVE-2023-35720, CVE-2024-3079, CVE-2024-3080
Release notes — disclosure 1.00
- Fixed command injection vulnerability.- Fixed the ARP poisoning vulnerability. Thanks to the contribution of Xin'an Zhou.- Fixed code execution in custom OVPN. Thanks to the contrubution of Jacob Baines.- Fixed the injection vulnerability in AiCloud.- Fixed stack buffer overflow in lighttpd. Special thanks to Viktor Edstrom. - Fixed CVE-2023-35720- Fixed the code execution vulnerability in AiCloud. Thanks to the contribution of chumen77.- Fixed the XSS and Self-reflected HTML injection vulnerability. Thanks to the contrubution of Redfox Cyber Security. - Fixed CVE-2024-3079 and CVE-2024-3080. Thanks to the contribution of swing from Chaitin Security Research Lab.*Please be advised that due to a security upgrade in AiMesh, we strongly recommend against downgrading to previous firmware versions, as this may lead to connection issues. Should you encounter any difficulties, resetting the AiMesh router to its default settings and re-establishing the mesh connection can resolve the problem.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_51915 10 July 2023
Cites CVE-2018-20505, CVE-2019-16168, CVE-2019-19645, CVE-2019-19646, CVE-2019-8457, CVE-2020-11655, CVE-2020-11656, CVE-2020-12695, CVE-2020-13434, CVE-2020-13435, CVE-2020-13631, CVE-2020-28926, CVE-2022-3109, CVE-2022-3964, CVE-2022-48434, CVE-2023-0464, CVE-2023-28319, CVE-2023-28321, CVE-2023-28322, CVE-2023-35086, CVE-2023-35087, CVE-2023-35720, CVE-2023-38031, CVE-2023-38032, CVE-2023-38033, CVE-2023-39236, CVE-2023-39237, CVE-2023-39239
Release notes — disclosure 0.84
Security updates:-Fixed the cfg server vulnerability.-Fixed the vulnerability in the logmessage function CVE-2023-35086/ CVE-2023-35087.-Fixed lighttpd vulnerability, CVE-2023-35720.-Fixed several curl vulnerabilities including CVE-2023-28322, CVE-2023-28321, and CVE-2023-28319.-Fixed FFmpeg vulnerabilities, specifically CVE-2022-3964, CVE-2022-48434, and CVE-2022-3109.-Fixed OpenSSL vulnerability, CVE-2023-0464.-Fixed ReadyMedia vulnerabilitym CVE-2020-28926.-Fixed UPnP vulnerability CVE-2020-12695.-Upgraded sqlighte and resolved CVE-2020-11656 / CVE-2019-19646 / CVE-2019-8457 / CVE-2020-11655 / CVE-2018-20505 / CVE-2019-16168 / CVE-2019-19645 / CVE-2020-13435 / CVE-2020-13631 / CVE-2020-13434-Strengthened protection against SSH brute force attacks.-Fixed CVE-2023-39239. Thanks to Swings and Wang Duo from Chaitin Security Research Lab , C0ss4ck from Bytedance Wuheng Lab, 费新程 from X1cT34m.- Patched several command injection vulnerabilities, CVE-2023-38031, CVE-2023-38032, CVE-2023-38033,CVE-2023-39236,CVE-2023-39237, Thanks to Jincheng Wang from X1cT34m Laboratory of Nanjing University of Posts and Telecommunications
Archived page, fetched 29 September 2026
-
3.0.0.4.386.51529 13 April 2023
Cites CVE-2023-28702, CVE-2023-28703
Release notes — disclosure 0.88
Security updates:-Fixed DoS vulnerabilities in firewall configuration pages. Thanks to Jinghe Gao's contribution.-Fixed DoS vulerabilities in httpd. Thanks to Howard McGreehan.-Fixed information disclosure vulnerability. Thanks to Junxu (Hillstone Network Security Research Institute) contribution.-Fixed CVE-2023-28702 and CVE-2023-28703. Thanks to Xingyu Xu(@tmotfl) contribution.-Fixed null pointer dereference vulnerabilities. Thanks to Chengfeng Ye, Prism Research Group - cse hkust contribution.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.51255 2 March 2023
Cites CVE-2018-116010, CVE-2022-263769
Release notes — disclosure 0.74
1.Fixed HTTP response splitting vulnerability.2.Fixed Samba related vulerabilities.3.Fixed cfg server security issues.4.Fixed Open redirect vulnerability.5.Fixed token authentication security issues.6.Fixed security issues on the status page.7.Fixed XSS vulnerability.8.Fixed CVE-2022-263769.Fixed CVE-2018-116010.Fixed IPv6-related bugs.11.Added a new login URL http://www.asusrouter.com to fixed the login issues.12.Optimize the AiMesh web interface13.Fixed network map UI bugs14.Fixed bugs related to Wi-Fi calling.15.Supported web history record exported.16.Fixed IPSec VPN server compatibility with Windows 10 VPN client.17.Improved AiMesh connection stability.18.Fixed IPTV issues.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.48260 25 March 2022
Cites CVE-2022-07782, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-255975
Release notes — disclosure 0.91
1. Fixed OpenSSL CVE-2022-07782. Added more security measures to block malware.3. Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.4. Fixed CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-255975. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.46092 3 March 2022
Cites CVE-2021-34174, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972
Release notes — disclosure 0.80
Security- Fixed string format stacks vulnerability- Fixed cross-site-scripting vulnerability- Fixed informational vulnerability.Thanks to Howard McGreehan.-Fixed SQL injection vulnerability-Fixed json file traversal vulnerability-Fixed plc/port file traversal vulnerability-Fixed stack overflow vulnerabilityThanks to HP of Cyber Kunlun Lab-Fixed authenticated stored XSS vulnerabilityThanks to Luke Walker – SmartDCC-Fixed LPD denial of service vulnerability-Fixed cfgserver heap overflow vulnerability-Fixed cfgserver denial of service vulnerabilityThanks to TianHe from BeFun Cyber Security Lab.-Fixed CVE-2021-34174, CVE-2022-23972, CVE-2022-23970, CVE-2022-23971, CVE-2022-23973Added more ISP profileDigi 1 - TMDigi 2 - TIMEDigi 3 - DigiDigi 4 - CTSDigi 5 - ALLODigi 6 - SACOFAMaxis - CTSMaxis - SACOFAMaxis - TNB/ALLOFixed AiMesh guest network issues.Fixed DDNS issues where the WAN IP is IPv6Fixed UI bugs in Administration --> feedback.Fixed time zone error.Improved the connection stability.Fixed IPSecVPN issues.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.45956 25 November 2021
Cites CVE-2015-8041, CVE-2016-2148, CVE-2016-4476, CVE-2016-6301, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, CVE-2018-1000120, CVE-2019-11555, CVE-2019-5481, CVE-2019-5482, CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497, CVE-2019-9498, CVE-2019-9499, CVE-2020-11810, CVE-2020-14305, CVE-2020-25643, CVE-2020-8169, CVE-2021-27803, CVE-2021-30004, CVE-2021-41435, CVE-2021-41436
Release notes — disclosure 0.95
This version includes several vulnerability patches.BusyBox- CVE-2016-2148- CVE-2016-6301- CVE-2018- 1000517cURL- CVE-2020-8169- CVE-2019-5481- CVE-2019-5482- CVE-2018-1000120- CVE-2018- 1000300- CVE-2018-16839Lighttpd- CVE-2018-19052Linux- CVE-2020-14305- CVE-2020-25643- CVE-2019-19052lldpd- CVE-2020-27827Avahi- CVE-2017-6519hostapd- CVE-2021-30004- CVE-2019-16275OpenVPN- CVE-2020-11810- CVE-2020-15078wpa- CVE-2021-30004- CVE-2021-27803- CVE-2019-11555- CVE-2019-9499- CVE-2019-9498- CVE-2019-9497- CVE-2019-9496- CVE-2019-9495- CVE-2019-9494- CVE-2017-13086- CVE-2017-13084- CVE-2017-13082- CVE-2016-4476- CVE-2015-8041- Fixed envrams exposed issue. Thanks to Quentin Kaiser from IoT Inspector Research Lab contribution.- Fixed Stored XSS vulnerability.- Fixed CVE-2021-41435, CVE-2021-41436. Thanks to Efstratios Chatzoglou, University of the Aegean Georgios Kambourakis, European Commission at the European Joint Research Centre Constantinos Kolias, University of Idaho.- Fixed Stack overflow vulnerability. Thanks to Jixing Wang (@chamd5) contribution.- Fixed information disclosure vulnerability .Thanks to CataLpa from DBappSecurity Co.,Ltd Hatlab and 360 Alpha Lab contribution.- Fixed httpd and Cfg server DoS vulnerability Thanks to Wei Fan from NSFOCUS GeWuLAB.- Fixed stack overflow vulnerability- Fixed DoS vulnerability Thanks for the contribution of Fans0n, le3d1ng, Mwen, daliy yang from 360 Future Security Labs
Archived page, fetched 29 September 2026
-
3.0.0.4.386.44470 14 July 2021
Release notes — disclosure 0.49
1. Improved system stability.2. Add JPNE v6plus support. (Beta release)3. Added Auto firmware upgrade in Administration-->Firwmare Upgrade4. Fixed envrams exposed issue. Thanks for Quentin Kaiser from IoT Inspector Research Lab contribution.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.42643 28 April 2021
Cites CVE-2021-3450
Release notes — disclosure 0.90
1. Fixed CVE-2021-3450, CVE2021-3449 OpenSSL related vulnerability.2. Fixed authentication bypass vulnerability. Special thank Chris Bellows, Darren Kemp – Atredis Partners contribution.3. Fixed PPTP and OpenVPN server username/password GUI bug.4. Fixed high CPU utilization issue.5. Fixed the fragattacks vulnerability.
Archived page, fetched 29 September 2026
-
9.0.0.4.386.41994 3 February 2021
Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25687
Release notes — disclosure 0.74
Security Fixed: Fixed CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686Please be noted this is a quick fix beta version for DNSmasq vulnerabilities. Refer to "Method 2: Update Manually" in https://www.asus.com/support/FAQ/1008000 to update this firmware.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.40451 22 October 2020
Release notes — disclosure 0.65
New features1. AiMesh 2.0- System optimization: one click in AiMesh to optimize the topology- System Ethernet backhaul mode, all nodes will only connect by ethernet, all bands will be released for wireless clients.- System factory default and reboot.- Client device reconnect, make the device to offline and online again.- Client device binding to specific AP.- Guest WiFi on all Mesh nodes (all node need to upgrade to 3.0.0.4.386 firmware)- Access nodes USB application.Connection priority and Ethernet backhaul mode introduction https://www.asus.com/support/FAQ/1044184How to setup ASUS AiMesh or ZenWiFi Mesh Ethernet backhaul under different conditionshttps://www.asus.com/support/FAQ/1044151/2. New Family interface in ASUS router App. ASUS Router App for iOS must greater or equal to iOS v1.0.0.5.75 Android version greater or equal to v1.0.0.5.743. The unit of the WiFi time scheduler goes to 1 minute.4. Support IPSec IKE v1 and IKE v2, and you can use the Windows 10 native VPN client program to connect to the router's IPSec VPN server. The Windows 10 new FAQ is in https://www.asus.com/support/FAQ/10335765. 2.4 and 5G on the network map could be configured in the same tab.6. Captcha for login can be disabled in administration -> system.7. Printer server port can be disabled on the USB app page.8. Clients which connect to the guest network can be viewed in the network map -->view list --> interface
Archived page, fetched 29 September 2026
-
3.0.0.4.384.82072 17 August 2020
Release notes — disclosure 0.32
- Fixed buffer overflow vulnerability- Fixed wireless performance drop issue after send the feedback.- Fixed static WAN IP connection issues.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81992 9 July 2020
Cites CVE-2017-15653, CVE-2020-12695
Release notes — disclosure 0.84
Security update - Fixed CVE-2020-12695 (CallStranger) - Fixed Reflected XSS vulnerability. - Fixed Directory traversal vulnerability. - Fixed CVE-2017-15653.The update server transport layer security was upgraded and the old protocol was removed. If your router firmware version is lower than 3.0.0.4.384.81352, please refer to the "Update Manually" section in https://www.asus.com/support/FAQ/1008000 to update the firmware.This version has more security processes. If you want to rollback to the previous version, please do a factory default reset.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81930 17 June 2020
Release notes — disclosure 0.32
- Fixed Let's encrypt certification renew bugs.- Improved web history page loading speed.- Fixed OpenVPN related bugs
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81918 27 May 2020
Release notes — disclosure 0.42
- Fixed game setting page UI bugs.- Fixed AiCloud share link bugs.- Fixed AiCloud connection bugs with AiMusic App.- Fixed Cloud sync bugs.- VPN clients can be turned on/off by the ASUS router app.- Fixed offline client removing problem with ASUS router app.- In the previous version, the certificate for https login needed to be installed again after system reboot, and this version fixed this problem.- Adaptive QoS supported more apps Work-From-Home: WeChat Work®, RescueAssist, Tencent/VooV Meeting® Learn-From-Home: LinkedIn Learning®, Binkist®, Skillshare®, edX® Media Streaming: SiriusXM®, Bilibili® Indoor training: The Sufferfest®, Bkool Fitness®, TrainerRoad®, Rouvy®
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81858 4 May 2020
Release notes — disclosure 0.40
- Improved connection stability. - Optimized CPU utilization. - Fixed some UI bugs. - Fixed login bugs. - Support router certificate export. After import the certificate to the computer you will not see the warning message when login with https.Please refer to https://www.asus.com/us/support/FAQ/1034294/
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81369 30 March 2020
Release notes — disclosure 0.55
1. Update Adaptive QoS categories: Help you to prioritize the mission-critical applications Those people who work-from-home & learn-from-home will greatly benefit from this new feature with optimized streaming experiences. New Supported Categories & Apps: - Video conferencing, including Microsoft Teams®, ZOOM®, Skype®, Google Hangouts®, BlueJeans®- Online learning, including Khan academy®, Udemy®, Coursera®, TED®, VIPKiD®, 51Talk®, XDF®, Xueersi®- Streaming, including YouTube®, Netflix®, HBO NOW®, Amazon Prime Video®, Disney+®, ESPN®, MLB.com®, iQIY®- Indoor training, including Zwift®, Peloton®, Onelap® Stay tuned and more apps are coming to the list soon! 2. Support Mobile Game Mode - One-click prioritizing your mobile device to the highest and ensure you the best mobile gaming experiences. - Install/Update ASUS Router App (Android supports later than 1.0.0.5.44; iOS supports later than 1.0.0.5.41)
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81352 10 March 2020
Cites CVE-2019-15126
Release notes — disclosure 0.66
- Fixed CVE-2019-15126 (Kr00k) vulnerability.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81351 20 November 2019
Release notes — disclosure 0.33
- Fixed a DDoS vulnerability.- Fixed Let's Encrypt related bugs.- Fixed folder creating bugs in Samba.- Fixed dual wan failover bugs while the primary wan type is L2TP.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.81049 5 September 2019
Release notes — disclosure 0.48
Security fix - Fixed a DDoS vulnerability. Thanks for Altin Thartori's contribution. Bug fix - Fixed web control interface login problem. - Fixed Network map clist list issues. - Fixed block internet access problem when clients connected to AiMesh node - Fixed Samba server compatibility issue. - Fixed OpenVPN related bugs. - Fixed schedule reboot bugs. - Improved AiMesh compatibility. - Improved system stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.45717 13 May 2019
Release notes — disclosure 0.49
- Fixed DDoS vulnerability.- Fixed AiCloud vulnerability. Thanks for Matt Cundari's contribution.- Fixed command injection vulnerability. Thanks for S1mba Lu's contribution.- Fixed buffer overflow vulnerability. Thanks for Javier Aguinaga's contribution.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.45713 18 April 2019
Cites CVE-2018-20334, CVE-2018-20336
Release notes — disclosure 0.91
Security Fix - Fixed CVE-2018-20334 - Fixed CVE-2018-20336 - Fixed null pointer issue. Thanks for CodeBreaker of STARLabs’ contribution. - Fixed AiCloud buffer overflow vulnerability. Thanks for Resecurity International's contribution. Bug Fix - Fixed AiMesh LAN IP issue when router using IPv6 WAN. - Fixed AIMesh connection issues. - Fixed Network Map related issues. - Fixed Download Master icon disappear issue. - Fixed LAN LED not blinking problem. - Fixed browser no response problem when enabled Traffic analyzer. - Fixed wireless mac filter input issue.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.45149 5 December 2018
Cites CVE-2018-14710, CVE-2018-14711, CVE-2018-14712, CVE-2018-14713, CVE-2018-14714, CVE-2018-17020, CVE-2018-17021, CVE-2018-17022
Release notes — disclosure 0.98
AiMesh- Improved AiMesh stability- Lyra, Lyra Mini, and Lyra Trio can be added as AiMesh node into RT-AC86U network. Please refer to https://www.asus.com/support/FAQ/1038071 for more detail.Security- Fixed CVE-2018-14710, CVE-2018-14711, CVE-2018-14712, CVE-2018-14713, CVE-2018-14714. Thanks for Rick Ramgattie's contribution.- Fixed AiCloud/ Samba account vulnerability. Thanks for Matthew Cundari's contribution.- Fixed DoS vulnerability. Thanks for Ruikai Liu's contribution.- Fixed CVE-2018-17020, CVE-2018-17021, CVE-2018-17022.- Fixed stored XSS vulnerability. Thanks for Duda Przemyslaw's contribution.- Updated OpenSSL library.Bug fixes and improvement- Improved wireless stability.- Modified “Dual Wan” user interface.- Modified “Port Forwarding” user interface.- Modified “Restore” user interface.- Fixed GUI bugs on user feedback page.- Fixed “Adaptive QoS” bugs.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.32799 14 September 2018
Release notes — disclosure 0.06
Fixed WIFI stability issue.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.32797 24 August 2018
Release notes — disclosure 0.60
AiMesh new features - Supported creating mesh system with new router, BlueCave. - Added Roaming block list in Advanced Settings --> Wireless. You can add devices into block list and this device will not be roamed between AiMesh nodes. - Supported ethernet onboarding. User can use ethernet cable. You can use ethernet cable to connect AiMesh router LAN port and AiMesh node WAN port first and run the adding node process to build the mesh system.Security fixes. - Fixed Reflected XSS vulnerability. - Fixed CSRF vulnerability. - Fixed command injection vulnerability. - Fixed stack buffer overflow vulnerability.Thanks for Rick Ramgattie contribution.Fixed Adaptive QoS upload bandwidth setting issue.Fixed 4-wires ethernet cable compatibility issues.Fixed USB hard drive over 2TB compatibility issues.Fixed Samba/FTP folder permission issues.Added USB3.0/2.0 mode switch setting in Administration --> System --> USB Settings.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.21140 10 July 2018
Release notes — disclosure 0.36
- [DDNS] Modified the procedure of DDNS service register under dual wan load balance mode- [WAN] Modified detect logic of internet connection- [AiMesh] Fixed AiMesh onboarding unsuccessfully once smart connect is enabled- [AiMesh] Modified AiMesh nodes notification procedure- [GUI] Fixed AiProtection GUI bugs.- [GUI] Updated OpenVPN server FAQ URL.
Archived page, fetched 29 September 2026
Evidence
2 archived pages sit behind this record, the earliest read on 2 August 2026. Everything above was read from them, and each is kept byte for byte so it can be checked after the vendor edits the original.
Identifiers: marketing_name RT-AC86U
Judged by lifecycle-1 on 29 September 2026.
How these verdicts are computed.