RT-AX1800U
Slowing down reasonably evidenced
updates are coming less often than this product's own history
159 days since the last release against a median gap of 56 (2.8x)
- Last firmware
- 24 April 2026 (5 months ago)
- Releases seen
- 15
- Update rhythm
- about every 2 months
- Support observed
- ≥4 years
- Vendor's promise
- no support period we can evaluate
- Patch latency
- not measurable — its changelogs name no CVE ids
Firmware history
-
3.0.0.4.386_69196 24 April 2026
Release notes — disclosure 0.33
Security enhancement:- Improved system security by addressing a heap buffer overflow vulnerability during cache handling.We recommend upgrading to this version to ensure up-to-date protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_69193 20 March 2026
Release notes — disclosure 0.34
Security Enhancements:- Strengthened input sanitization mechanism.- Enhanced system API validation for stronger protection consistency.- Strengthened command handling and system resource access controls.- Improved system logging and security event recording mechanisms.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_69155 31 October 2025
Release notes — disclosure 0.41
- Enhanced system stability.- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.- Implemented comprehensive validation and expanded command filtering in the web history API.- Strengthened input validation and directory handling in the VPN configuration upload interface.- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_69142 16 September 2025
Release notes — disclosure 0.45
Important: After installing this firmware, we strongly recommend performing a factory-default reset to activate every new security adjustment.Security Enhancements- Password Policy Upgrade – Minimum of 10 characters, including at least one letter, one digit, and one special character; disallows consecutive identical characters; hardens defense against brute-force attacks.- HTTPS on 8443 – Management interface now served over TLS by default.- UPnP Disabled – Universal Plug and Play starts in the off state for reduced surface exposure.- AiCloud Authentication Hardening (CWE-287) – Added layered verification.- Authentication Logic Refactor – Removed redundant code paths for a lean sign-in flow.- Memory Safety Guard (CWE-476) – Introduced null-reference protections across critical services.- Enhanced IPsec Parameter Validation – The existing input checks have been hardened.- Data Exposure Mitigation (CWE-200) – Reinforced controls on sensitive pathways.- Detailed Audit Trails – Expanded logging within the authentication module.System Improvements- Connection Stability – Core algorithms refined for steadier links.- Scheduling Accuracy – Timed tasks execute reliably under PPPoE, PPTP and L2TP WAN modes.- Client List Maintenance – Resolved an issue that prevented offline devices from being removed from the client list
Archived page, fetched 29 September 2026
-
3.0.0.4.386_69104 2 May 2025
Release notes — disclosure 0.49
1. Fixed the UI issue in Chrome.2. Fixed client binding issues in Mesh scenarios.3. Enhanced input parameter handling techniques to improve data processing stability and system security.4. Enhance system access control mechanisms.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_69086 5 November 2024
Release notes — disclosure 0.58
1. Strengthened input validation and data processing workflows to further protect information security.2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.3. Enhanced device security through improved buffer handling in connection features.4. Refined data handling processes, ensuring secure and accurate information management.5. Enhanced file access control mechanisms, promoting a more secure operating environment.6. Strengthened certificate protection, providing enhanced data security.7. Fixed GUI bugs
Archived page, fetched 29 September 2026
-
3.0.0.4.386_69061 15 September 2023
Release notes — disclosure 0.31
Fixed v6plus related issues and added support for OCN.
Archived page, fetched 29 September 2026
-
3.0.0.4.386_69021 21 August 2023
Cites CVE-2018-20505, CVE-2019-16168, CVE-2019-19645, CVE-2019-19646, CVE-2019-8457, CVE-2020-11655, CVE-2020-11656, CVE-2020-13434, CVE-2020-13435, CVE-2020-13631, CVE-2023-0464, CVE-2023-28319, CVE-2023-28321, CVE-2023-28322, CVE-2023-35720
Release notes — disclosure 0.88
New features:-iPhone/Android USB auto backup WAN allows you to connect your phone to the router’s USB port and use it as an internet source. Please refer to https://www.asus.com/support/FAQ/1050074/-DDNS transfer allows you to transfer your ASUS DDNS hostname from your original router to the new one. Please refer to https://www.asus.com/support/FAQ/1048684/Security updates:-Allowed binding DDNS to a user's account to reduce the risk of MITM attacks-Fixed the cfg server vulnerability.-Fixed lighttpd vulnerability, CVE-2023-35720.-Fixed several curl vulnerabilities including CVE-2023-28322, CVE-2023-28321, and CVE-2023-28319.-Fixed OpenSSL vulnerability, CVE-2023-0464.-Patched several command injection vulnerabilities.-Upgraded sqlighte and resolved CVE-2020-11656 / CVE-2019-19646 / CVE-2019-8457 / CVE-2020-11655 / CVE-2018-20505 / CVE-2019-16168 / CVE-2019-19645 / CVE-2020-13435 / CVE-2020-13631 / CVE-2020-13434
Archived page, fetched 29 September 2026
-
3.0.0.4.386_69020 3 August 2023
Cites CVE-2018-20505, CVE-2019-16168, CVE-2019-19645, CVE-2019-19646, CVE-2019-8457, CVE-2020-11655, CVE-2020-11656, CVE-2020-13434, CVE-2020-13435, CVE-2020-13631, CVE-2023-0464, CVE-2023-28319, CVE-2023-28321, CVE-2023-28322, CVE-2023-35720
Release notes — disclosure 0.89
New features:-iPhone/Android USB auto backup WAN allows you to connect your phone to the router’s USB port and use it as an internet source. Please refer to https://www.asus.com/support/FAQ/1050074/-DDNS transfer allows you to transfer your ASUS DDNS hostname from your original router to the new one. Please refer to https://www.asus.com/support/FAQ/1048684/Security updates:-Allowed binding DDNS to a user's account to reduce the risk of MITM attacks-Fixed login password issue in specific SKU.-Fixed the cfg server vulnerability.-Fixed lighttpd vulnerability, CVE-2023-35720.-Fixed several curl vulnerabilities including CVE-2023-28322, CVE-2023-28321, and CVE-2023-28319.-Fixed OpenSSL vulnerability, CVE-2023-0464.-Patched several command injection vulnerabilities.-Upgraded sqlighte and resolved CVE-2020-11656 / CVE-2019-19646 / CVE-2019-8457 / CVE-2020-11655 / CVE-2018-20505 / CVE-2019-16168 / CVE-2019-19645 / CVE-2020-13435 / CVE-2020-13631 / CVE-2020-13434
Archived page, fetched 29 September 2026
-
3.0.0.4.386_69019 21 July 2023
Cites CVE-2018-20505, CVE-2019-16168, CVE-2019-19645, CVE-2019-19646, CVE-2019-8457, CVE-2020-11655, CVE-2020-11656, CVE-2020-13434, CVE-2020-13435, CVE-2020-13631, CVE-2023-0464, CVE-2023-28319, CVE-2023-28321, CVE-2023-28322, CVE-2023-35720
Release notes — disclosure 0.88
New features:-iPhone/Android USB auto backup WAN allows you to connect your phone to the router’s USB port and use it as an internet source. Please refer to https://www.asus.com/support/FAQ/1050074/-DDNS transfer allows you to transfer your ASUS DDNS hostname from your original router to the new one. Please refer to https://www.asus.com/support/FAQ/1048684/Security updates:-Allowed binding DDNS to a user's account to reduce the risk of MITM attacks-Fixed the cfg server vulnerability.-Fixed lighttpd vulnerability, CVE-2023-35720.-Fixed several curl vulnerabilities including CVE-2023-28322, CVE-2023-28321, and CVE-2023-28319.-Fixed OpenSSL vulnerability, CVE-2023-0464.-Patched several command injection vulnerabilities.-Upgraded sqlighte and resolved CVE-2020-11656 / CVE-2019-19646 / CVE-2019-8457 / CVE-2020-11655 / CVE-2018-20505 / CVE-2019-16168 / CVE-2019-19645 / CVE-2020-13435 / CVE-2020-13631 / CVE-2020-13434
Archived page, fetched 29 September 2026
-
3.0.0.4.386.68691 30 March 2023
Release notes — disclosure 0.54
1. Fixed an issue with changing passwords.2. Fixed bandwidth errors when 5GHz channel is fixed at 116.3. Improved security by upgrading to SHA256.4. Added support for disabling 11b on 2.4GHz band 5. Improved DDNS functionality and added HE.NET6. Improved smart connect function.7. Added LED on/off feature as Aimesh node.8. Optimized AiMesh Topology page.9. Improved Aimesh stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.68526 7 February 2023
Release notes — disclosure 0.32
1.Improved JP SKU initial setup process.2.Improved system stability.3.Fixed multi-language related GUI bugs.4.Improved AiMesh stability.5.Fixed IPSec VPN related performance issue.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.68383 22 December 2022
Release notes — disclosure 0.33
1.Improved system stability.2.Fixed firmware upgrade issue in the latest step of the initial setup process.3.Fixed web user interface display bugs after disabling wireless.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.68129 21 October 2022
Release notes — disclosure 0.56
1. Fixed httpd error when turning off the radio. 2. Fixed connection issue when SSID containing space and UTF8 under AiMesh or Repeater mode.3. Fixed IPv6 manual DNS setting bugs. 4. Fixed UI display error of USB types. 5. Fixed AiMesh related issue. 6. Added new entrance for web GUI http://www.asusrouter.com.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.67508 30 May 2022
Release notes — disclosure 0.41
1. Supported AiMesh function.2. Fixed IPTV bugs.3. Fixed WPA2 PSK/WPA3 PSK mix mode issues.4. Improved system stability.
Archived page, fetched 29 September 2026
Evidence
One archived page sits behind this record, the earliest read on 2 August 2026. Everything above was read from it, and each is kept byte for byte so it can be checked after the vendor edits the original.
Identifiers: marketing_name RT-AX1800U
Judged by lifecycle-1 on 30 September 2026.
How these verdicts are computed.