Device Support-Lifespan Observatory

What vendors do, not what they announce.

ASUS

RT-AX86U ZAKU II EDITION

Gone quiet well evidenced

no firmware for long enough to stand out against its own record

527 days since the last release against a median gap of 61 (8.6x)

Sign in to be emailed when this verdict changes.
Last firmware
21 April 2025 (1 year ago)
Releases seen
16
Update rhythm
about every 2 months
Support observed
≥4 years
Vendor's promise
no support period we can evaluate
Patch latency
not measurable — its changelogs name no CVE ids

Firmware history

  1. 3.0.0.4.388_24339 21 April 2025

    Release notes — disclosure 0.31
    Improved compatibility with certain IoT devices.
  2. 3.0.0.4.388_24338 25 March 2025

    Release notes — disclosure 0.49
    1. Fixed the UI issue in Chrome.2. Fixed client binding issues in Mesh scenarios.3. Enhanced input parameter handling techniques to improve data processing stability and system security.4. Enhance system access control mechanisms.
  3. 3.0.0.4.388_24323 28 November 2024

    Release notes — disclosure 0.37
    1.Strengthened input validation and data processing workflows to further protect information security.2.Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.3.Enhanced device security through improved buffer handling in connection features.4.Refined data handling processes, ensuring secure and accurate information management.5.Enhanced file access control mechanisms, promoting a more secure operating environment.6.Strengthened certificate protection, providing enhanced data security.
  4. 3.0.0.4.388_24243 13 May 2024

    Cites CVE-2023-35720, CVE-2024-3079, CVE-2024-3080

    Release notes — disclosure 1.00
    - Fixed command injection vulnerability. - Fixed the ARP poisoning vulnerability. Thanks to the contribution of Xin'an Zhou. - Fixed code execution in custom OVPN. Thanks to the contrubution of Jacob Baines. - Fixed the injection vulnerability in AiCloud. - Fixed stack buffer overflow in lighttpd. Special thanks to Viktor Edstrom. - Fixed CVE-2023-35720 - Fixed the code execution vulnerability in AiCloud. Thanks to the contribution of chumen77. - Fixed the XSS and Self-reflected HTML injection vulnerability. Thanks to the contrubution of Redfox Cyber Security. - Fixed CVE-2024-3079 and CVE-2024-3080. Special thanks to Weiming Shi *Please be advised that due to a security upgrade in AiMesh, we strongly recommend against downgrading to previous firmware versions, as this may lead to connection issues. Should you encounter any difficulties, resetting the AiMesh router to its default settings and re-establishing the mesh connection can resolve the problem.
  5. 3.0.0.4.388_24231 7 November 2023

    Release notes — disclosure 0.45
    Bug Fixes and Enhancements:- Fixed v6plus related Issues.- Fixed ipv6 network service filter not work.- Resolved an issue that caused hostname errors in the DDNS service.- Resolved OpenVPN Server TAP Mode Issue.- Fixed the problem that the AiCloud app cannot add router on Android 9.- Ensured consistent display of client status on the WireGuard server.- Enhanced system stability when accessing the WireGuard Server with DMZ enabled.- Improved stability when enabling or disabling the WireGuard server.- Optimized memory utilization and fixed an occasional server error when registering DDNS with an app.- Corrected a bug encountered when adding a rule to the network services filter.Security Fixes:- Fixed several curl vulnerabilities.- Fixed FFmpeg vulnerabilities.- Corrected an OpenVPN vulnerability categorized as CWE-134.- Strengthened protection against SSH brute force attacks.- Fixed OpenSSL vulnerabilities.
  6. 3.0.0.4.388.23285 15 May 2023

    Cites CVE-2023-28702, CVE-2023-28703

    Release notes — disclosure 1.00
    New features:-Built-in Surfshark in VPN Fusion allows you to surf the internet anonymously and securely from anywhere by encrypting connections. Please refer to https://asus.click/SurfsharkVPN-iPhone/Android USB auto backup WAN allows you to connect your phone to the router’s USB port and use it as an internet source. Please refer to https://asus.click/AutobackupWAN-DDNS transfer allows you to transfer your ASUS DDNS hostname from your original router to the new one. Please refer to https://asus.click/ASUSDDNSBug fixes and functionality modifications:-Resolved the issue with login and password changes.-Resolved the IPSec VPN connection issues.-Resolved the Instant Guard connection issues.-Fixed the AiCloud login issue after unplugging and plugging the HDD into the USB port.-Fixed the issue where Traffic Analyzer sometimes couldn't record data.-Fixed the time display issue for the preferred upgrade time in the Auto Firmware Upgrade function.-Fine-tuned the description for port status.-Enabled DynDNS and No-IP DDNS to use IPv6.-Fixed AiMesh preferred AP identification in site survey results.-Updated timezone list for Greenland, Mexico, and Iran.-Modified the USB application option text in dual WAN.-Allowed WireGuard Server clients to access the Samba server.-Fixed memory leak issue.-Enabled the failback function when using the iOS/Android USB backup WAN.-The ARP response issue has been resolved, along with the connection issue between the router and the ROG Phone 6 and 7.-Resolved the issue where the USB path is not displayed on the Media Server page in the AiMesh nodeSecurity updates:-Enabled and supported ECDSA certificates for Let's Encrypt.-Enhanced protection for credentials.-Enhanced protection for OTA firmware updates.-Fixed DoS vulnerabilities in firewall configuration pages. Thanks to Jinghe Gao's contribution.-Fixed DoS vulerabilities in httpd. Thanks to Howard McGreehan.-Fixed information disclosure vulnerability. Thanks to Junxu (Hillstone Network Security Research Institute) contribution.-Fixed CVE-2023-28702 and CVE-2023-28703. Thanks to Xingyu Xu(@tmotfl) contribution.-Fixed null pointer dereference vulnerabilities. Thanks to Chengfeng Ye, Prism Research Group - cse hkust contribution.-Fixed the cfg server vulnerability. Thanks to Swing and Wang Duo from Chaitin Security Research Lab.-Fixed the vulnerability in the logmessage function. Thanks to Swing and Wang Duo from Chaitin Security Research Lab C0ss4ck from Bytedance Wuheng Lab, Feixincheng from X1cT34m
  7. 3.0.0.4.388.22525 7 February 2023

    Cites CVE-2022-468712

    Release notes — disclosure 0.70
    1.Fixed CVE-2022-468712.Fixed Client DOM Stored XSS.3.Improved AiMesh backhaul stability.4.Fixed AiMesh topology UI bugs.5.Fixed the reboot issue when assigning specific clients in VPN fusion.6.Fixed the VPN fusion bug when importing the Surfshark WireGuard conf file.7.Fixed network map bugs.
  8. 3.0.0.4.388.22068 19 December 2022

    Release notes — disclosure 0.44
    1. Improved system stability.2. Fixed the IPsec VPN compatibility issue with Win10.3. Fixed the VPN fusion user interface issues under the HTTPS connection.4. Fixed Client DOM Stored XSS vulnerability.5. Improved Wireguard performance.
  9. 3.0.0.4.388.21709 24 November 2022

    Cites CVE-2022-406179

    Release notes — disclosure 0.91
    1. Optimized memory usage and improved system stability.2. Fixed USB HDD compatibility issue with the Time machine.3. Added a new web GUI login URL http://www.asusrouter.com4. Fixed IPTV compatibility issue with Movistar. Thanks to Sergio de Luz from RedesZone.net.5. Fixed VPN fusion, AiMesh, and Network map GUI bugs.6. Fixed WAN compatibility issue with Starlink router.7. Fixed miniupnpc vulnerabilities, CVE-2015-603, CVE-2017-10004948. Fixed IPSec server vulnerability, CVE-2022-406179. Improved connection speed with Verizon FIOS.
  10. 3.0.0.4.388.20566 30 September 2022

    Cites CVE-2018-1160

    Release notes — disclosure 1.00
    Try more on ASUSWRT 2022 with new features at https://asus.click/ASUSWRT20221. Supported WireGuard VPN server and client.2. Supported VPN fusion. It can easily achieve VPN connection to network devices like Smart TV, Game consoles and without installing the VPN client software.3. Supported new devices connection notification.4. Supported connection diagnostic on the ASUS router app.5. Supported Instant Guard 2.0 which helps easily invite family or friends to join the VPN connection.6. Upgraded parental control and added reward, new scheduler for flexible setting7. Fixed USB icon issue in port status.8. Fixed HTTP response splitting vulnerability. Thanks to Efstratios Chatzoglou, University of the Aegean.9. Fixed status page HTML vulnerability. Thanks to David Ward.10. Fixed CVE-2018-1160. Thanks to Steven Sroba.11. Fixed cfg_server security issue.
  11. 3.0.0.4.386.49599 12 July 2022

    Release notes — disclosure 0.05
    Imprtoved connection stability.
  12. 3.0.0.4.386.49447 20 June 2022

    Cites CVE-2021-341743, CVE-2022-07782, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-263766

    Release notes — disclosure 0.96
    1. Fixed OpenSSL CVE-2022-07782. Fixed CVE-2021-341743. Added more security measures to block malware.4. Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.5. Fixed CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-263766. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.7. Supported Safe Browsing in the router app to filter explicit content from search results. You can set it in the router app --> Devices or Family.8. Improved system stability.9. Fixed anomalous 802.11 frame issues. Thanks to Kari Hulkko and Tuomo Untinen from The Synopsys Cybersecurity Research Center (CyRC). Issue was found by using Defensics Fuzz Testing Tool.
  13. 3.0.0.4.386.46061 11 January 2022

    Release notes — disclosure 0.37
    Security- Fixed string format stacks vulnerability- Fixed cross-site-scripting vulnerability- Fixed informational vulnerability.Thanks to Howard McGreehan.-Fixed SQL injection vulnerability-Fixed json file traversal vulnerability-Fixed plc/port file traversal vulnerability-Fixed stack overflow vulnerabilityThanks to HP of Cyber Kunlun Lab-Fixed authenticated stored XSS vulnerabilityThanks to Luke Walker – SmartDCC-Fixed LPD denial of service vulnerability-Fixed cfgserver heap overflow vulnerability-Fixed cfgserver denial of service vulnerabilityThanks to TianHe from BeFun Cyber Security Lab.Added more ISP profile Digi 1 - TMDigi 2 - TIMEDigi 3 - DigiDigi 4 - CTSDigi 5 - ALLODigi 6 - SACOFAMaxis - CTSMaxis - SACOFAMaxis - TNB/ALLOFixed AiMesh guest network issues.Fixed DDNS issues where the WAN IP is IPv6Fixed UI bugs in Administration --> feedback. Fixed time zone error.Improved the connection stability.
  14. 3.0.0.4.386.45934 11 November 2021

    Release notes — disclosure 0.48
    1. Fixed Let's encrypt related bugs.2. Fixed httpd vulnerability3. Fixed stack overflow vulnerability4. Fixed DoS vulnerabilityThanks for the contribution of Fans0n、le3d1ng、Mwen、daliy yang from 360 Future Security Labs
  15. 3.0.0.4.386.45898 7 October 2021

    Cites CVE-2021-41435, CVE-2021-41436

    Release notes — disclosure 0.77
    1.Fixed AiMesh web page multi-language issues.2.Fixed Stored XSS vulnerability.3.Fixed CVE-2021-41435, CVE-2021-41436.Thanks to Efstratios Chatzoglou, University of the AegeanGeorgios Kambourakis, European Commission at the European Joint Research CentreConstantinos Kolias, University of Idaho.4.Fixed Stack overflow vulnerability. Thanks to Jixing Wang (@chamd5) contribution.5.Fixed information disclosure vulnerability .Thanks to CataLpa from DBappSecurity Co.,Ltd Hatlab and 360 Alpha Lab contribution.
  16. 3.0.0.4.386.45375 31 August 2021

    Cites CVE-2016-2148, CVE-2016-4476, CVE-2016-6301, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, CVE-2018-1000120, CVE-2019-11555, CVE-2019-5481, CVE-2019-5482, CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497, CVE-2019-9498, CVE-2019-9499, CVE-2020-11810, CVE-2020-14305, CVE-2020-25643, CVE-2020-8169, CVE-2021-27803, CVE-2021-30004

    Release notes — disclosure 0.86
    This version includes several vulnerability patches.BusyBox- CVE-2016-2148- CVE-2016-6301- CVE-2018- 1000517cURL- CVE-2020-8169- CVE-2019-5481- CVE-2019-5482- CVE-2018-1000120- CVE-2018- 1000300- CVE-2018-16839Lighttpd- CVE-2018-19052Linux- CVE-2020-14305- CVE-2020-25643- CVE-2019-19052lldpd- CVE-2020-27827Avahi- CVE-2017-6519hostapd- CVE-2021-30004- CVE-2019-16275OpenVPN- CVE-2020-11810- CVE-2020-15078wpa- CVE-2021-30004- CVE-2021-27803- CVE-2019-11555- CVE-2019-9499- CVE-2019-9498- CVE-2019-9497- CVE-2019-9496- CVE-2019-9495- CVE-2019-9494- CVE-2017-13086- CVE-2017-13084- CVE-2017-13082- CVE-2016-4476- CVE-2015-8041Fixed DoS vulnerability from spoofed sae authentication frame. Thanks to Efstratios Chatzoglou, University of the Aegean, Georgios Kambourakis, European Commission at the European Joint Research Centre, and Constantinos Kolias, University of Idaho.Fixed envrams exposed issue. Thanks to Quentin Kaiser from IoT Inspector Research Lab contribution

Evidence

One archived page sits behind this record, the earliest read on 2 August 2026. Everything above was read from it, and each is kept byte for byte so it can be checked after the vendor edits the original.

Identifiers: marketing_name RT-AX86U ZAKU II EDITION

Judged by lifecycle-1 on 30 September 2026. How these verdicts are computed.

Machine-readable: JSON · RSS