Device Support-Lifespan Observatory

What vendors do, not what they announce.

ASUS

RT-AX56U

Actively updated well evidenced

firmware is arriving about as often as it always has

147 days since the last release against a median gap of 126 (1.2x)

Sign in to be emailed when this verdict changes.
Last firmware
6 May 2026 (5 months ago)
Releases seen
16
Update rhythm
about every 4 months
Support observed
≥6 years
Vendor's promise
no support period we can evaluate
Patch latency
not measurable — its changelogs name no CVE ids

Firmware history

  1. 3.0.0.4.386_52090 6 May 2026

    Release notes — disclosure 0.40
    Security Fixes- Enhanced system security by addressing an unsafe remote script execution mechanism in.- Improved system security by addressing a heap buffer overflow vulnerability during cache handling. We recommend upgrading to this version to ensure up-to-date protection.
  2. 3.0.0.4.386_52088 16 March 2026

    Release notes — disclosure 0.37
    Improvements:Optimized Wi-Fi roaming stability for devices supporting 802.11k but not allowing 11v.Improved Wi-Fi roaming compatibility and stability for iOS 26 devices.Refined accessibility-related UI and interaction details.Improved overall remote connection stability.Security Enhancements:Strengthened input sanitization mechanismEnhanced system API validation for stronger protection consistency.Strengthened command handling and system resource access controls.Improved system logging and security event recording mechanisms
  3. 3.0.0.4.386_52049 27 October 2025

    Release notes — disclosure 0.42
    - Enhanced system stability.- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.- Implemented comprehensive validation and expanded command filtering in the web history API.- Fixed a privilege escalation vector in the IFTTT token exchange mechanism.- Strengthened input validation and directory handling in the VPN configuration upload interface.- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
  4. 3.0.0.4.386_51725 17 March 2025

    Release notes — disclosure 0.33
    1.Fixed the UI issue in Chrome.2.Enhanced input parameter handling techniques to improve data processing stability and system security.3.Enhance system access control mechanisms.
  5. 3.0.0.4.386_51712 11 November 2024

    Release notes — disclosure 0.58
    1. Strengthened input validation and data processing workflows to further protect information security.2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.3. Enhanced device security through improved buffer handling in connection features.4. Refined data handling processes, ensuring secure and accurate information management.5. Enhanced file access control mechanisms, promoting a more secure operating environment.6. Strengthened certificate protection, providing enhanced data security.
  6. 3.0.0.4.386_51679 29 May 2024

    Release notes — disclosure 0.61
    Security updates:Fixed command injection vulnerability.Fixed the ARP poisoning vulnerability. Fixed code execution in custom OVPN. Fixed the injection vulnerability in AiCloud.Fixed stack buffer overflow in lighttpd. Fixed CVE-2023-35720Fixed the code execution vulnerability in AiCloud. Fixed the XSS and Self-reflected HTML injection vulnerability. *Please be advised that due to a security upgrade in AiMesh, we strongly recommend against downgrading to previous firmware versions, as this may lead to connection issues. Should you encounter any difficulties, resetting the AiMesh router to its default settings and re-establishing the mesh connection can resolve the problem.
  7. 3.0.0.4.386.51665 18 May 2023

    Cites CVE-2023-28702, CVE-2023-28703, CVE-2023-35086, CVE-2023-35087

    Release notes — disclosure 0.99
    Security updates:-Enabled and supported ECDSA certificates for Let's Encrypt.-Enhanced protection for credentials.-Enhanced protection for OTA firmware updates.-Fixed DoS vulnerabilities in firewall configuration pages. Thanks to Jinghe Gao's contribution.-Fixed DoS vulerabilities in httpd. Thanks to Howard McGreehan.-Fixed information disclosure vulnerability. Thanks to Junxu (Hillstone Network Security Research Institute) contribution.-Fixed CVE-2023-28702 and CVE-2023-28703. Thanks to Xingyu Xu(@tmotfl) contribution.-Fixed null pointer dereference vulnerabilities. Thanks to Chengfeng Ye, Prism Research Group - cse hkust contribution.-Fixed the cfg server vulnerability. Thanks to Swing and Wang Duo from Chaitin Security Research Lab. -Fixed the vulnerability in the logmessage function CVE-2023-35086/ CVE-2023-35087. Thanks to Swing and Wang Duo from Chaitin Security Research Lab C0ss4ck from Bytedance Wuheng Lab, Feixincheng from X1cT34m.
  8. 3.0.0.4.386.49380 23 June 2022

    Cites CVE-2021-341743, CVE-2022-07782, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-263766

    Release notes — disclosure 0.92
    1. Fixed OpenSSL CVE-2022-07782. Fixed CVE-2021-341743. Added more security measures to block malware.4. Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.5. Fixed CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-263766. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.7. Supported Safe Browsing in the router app to filter explicit content from search results. You can set it in the router app --> Devices or Family.8. Improved system stability.
  9. 3.0.0.4.386.45934 16 November 2021

    Release notes — disclosure 0.55
    1. Fixed Let's encrypt related bugs. 2. Fixed httpd and Cfg server DoS vulnerability Thanks to Wei Fan from NSFOCUS GeWuLAB.3. Fixed stack overflow vulnerability 4. Fixed DoS vulnerabilityThanks for the contribution of Fans0n、le3d1ng、Mwen、daliy yang from 360 Future Security Labs
  10. 3.0.0.4.386.45898 7 October 2021

    Cites CVE-2015-8041, CVE-2016-2148, CVE-2016-4476, CVE-2016-6301, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, CVE-2018-1000120, CVE-2019-11555, CVE-2019-5481, CVE-2019-5482, CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497, CVE-2019-9498, CVE-2019-9499, CVE-2020-11810, CVE-2020-14305, CVE-2020-25643, CVE-2020-8169, CVE-2021-27803, CVE-2021-30004, CVE-2021-41435, CVE-2021-41436

    Release notes — disclosure 0.95
    This version includes several vulnerability patches.BusyBox- CVE-2016-2148- CVE-2016-6301- CVE-2018-1000517cURL- CVE-2020-8169- CVE-2019-5481- CVE-2019-5482- CVE-2018-1000120- CVE-2018- 1000300- CVE-2018-16839Lighttpd- CVE-2018-19052Linux- CVE-2020-14305- CVE-2020-25643- CVE-2019-19052lldpd- CVE-2020-27827Avahi- CVE-2017-6519hostapd- CVE-2021-30004- CVE-2019-16275OpenVPN- CVE-2020-11810- CVE-2020-15078wpa- CVE-2021-30004- CVE-2021-27803- CVE-2019-11555- CVE-2019-9499- CVE-2019-9498- CVE-2019-9497- CVE-2019-9496- CVE-2019-9495- CVE-2019-9494- CVE-2017-13086- CVE-2017-13084- CVE-2017-13082- CVE-2016-4476- CVE-2015-8041-Fixed DoS vulnerability from spoofed sae authentication frame. Thanks to Efstratios Chatzoglou, University of the Aegean, Georgios Kambourakis, European Commission at the European Joint Research Centre, and Constantinos Kolias, University of Idaho.-Fixed envrams exposed issue. Thanks to Quentin Kaiser from IoT Inspector Research Lab contribution.-Fixed AiMesh web page multi-language issues.-Fixed Stored XSS vulnerability.-Fixed CVE-2021-41435, CVE-2021-41436.Thanks to Efstratios Chatzoglou, University of the AegeanGeorgios Kambourakis, European Commission at the European Joint Research CentreConstantinos Kolias, University of Idaho.-Fixed Stack overflow vulnerability. Thanks to Jixing Wang (@chamd5) contribution.-Fixed information disclosure vulnerability .Thanks to CataLpa from DBappSecurity Co.,Ltd Hatlab and Yao Chen(@ysmilec) of 360 Alpha Lab
  11. 3.0.0.4.386.44266 14 July 2021

    Release notes — disclosure 0.49
    1. Improved system stability.2. Added IPv6+ in WAN-> Internet Connection.3. Added Auto firmware upgrade in Administration-->Firwmare Upgrade4. Fixed envrams exposed issue. Thanks for Quentin Kaiser from IoT Inspector Research Lab contribution.
  12. 3.0.0.4.386.42808 11 May 2021

    Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-256862, CVE-2020-25687

    Release notes — disclosure 1.00
    1. AiMesh 2.0- System optimization: one click in AiMesh to optimize the topology- System Ethernet backhaul mode, all nodes will only connect by ethernet, all bands will be released for wireless clients.- System factory default and reboot.- Client device reconnect, make the device to offline and online again.- Client device binding to specific AP.- Guest WiFi on all Mesh nodes (all node need to upgrade to 3.0.0.4.386 firmware)- Access nodes USB application.Connection priority and Ethernet backhaul mode introductionhttps://www.asus.com/support/FAQ/1044184How to setup ASUS AiMesh or ZenWiFi Mesh Ethernet backhaul under different conditionshttps://www.asus.com/support/FAQ/1044151/2. New Family interface in ASUS router App.ASUS Router App for iOS must greater or equal to iOS v1.0.0.5.75Android version greater or equal to v1.0.0.5.743. The unit of the WiFi time scheduler goes to 1 minute.4. Support IPSec IKE v1 and IKE v2, and you can use the Windows 10 native VPN client program to connect to the router's IPSec VPN server. The Windows 10 new FAQ is in https://www.asus.com/support/FAQ/10335765. 2.4 and 5G on the network map could be configured in the same tab.6. Captcha for login can be disabled in administration -> system.7. Printer server port can be disabled on the USB app page.8. Clients which connect to the guest network can be viewed in the network map -->view list --> interface9. Fix Lets encrypt not working properly.10. Add IPTV supports for specific region.Security Fix:1. Fixed CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-256862. Upgrade dropbear to version 2020.813. Fix buffer overflow vulnerability4. Fix slowloris denial of service attack.5. Fix authentication bypass vulnerability.6. Fixed the fragattacks vulnerability.
  13. 3.0.0.4.384.10290 3 February 2021

    Release notes — disclosure 0.31
    - Improved system stability.- Fixed Let’s Encrypt not working properly issue
  14. 9.0.0.4.386.41994 2 February 2021

    Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25687

    Release notes — disclosure 0.74
    Security Fixed: Fixed CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686Please be noted this is a quick fix beta version for DNSmasq vulnerabilities. Refer to "Method 2: Update Manually" in https://www.asus.com/support/FAQ/1008000 to update this firmware.
  15. 3.0.0.4.384.9428 26 November 2020

    Release notes — disclosure 0.31
    - Fix LED abnormal during start up- Improve system stability
  16. 3.0.0.4.384.8253 17 January 2020

    Release notes — disclosure 0.06
    - Improve stability- Fix 1024QAM GUI issue
  17. 3.0.0.4.384.7764 17 December 2019

    Release notes — disclosure 0.30
    - Initial release

Evidence

One archived page sits behind this record, the earliest read on 2 August 2026. Everything above was read from it, and each is kept byte for byte so it can be checked after the vendor edits the original.

Identifiers: marketing_name RT-AX56U

Judged by lifecycle-1 on 30 September 2026. How these verdicts are computed.

Machine-readable: JSON · RSS