RT-AX92U
Actively updated well evidenced
firmware is arriving about as often as it always has
48 days since the last release against a median gap of 68 (0.7x)
- Last firmware
- 13 August 2026 (2 months ago)
- Releases seen
- 29
- Update rhythm
- about every 2 months
- Support observed
- ≥7 years
- Vendor's promise
- no support period we can evaluate
- Patch latency
- not measurable — its changelogs name no CVE ids
Firmware history
-
3.0.0.4.388_23842 13 August 2026
Release notes — disclosure 0.45
New Features- New Time Zone Options: Added "Vancouver, Whitehorse (PST7)" and "Edmonton, Yellowknife (MST6)" time zone options for Canada.Bug Fixes and Enhancements- Improved stability during the AiMesh node setup process.- Strengthened firewall rule configuration for UPnP, improving port-forwarding stability and firewall rule restoration reliability.Security Fixes- Strengthened data handling in Networks configuration functions.- Improved data validation in Networks rule list processing.- Fixed a data-handling issue in the DNS query caching component.- Strengthened verification when a software component downloads external resources, improving connection security.- Adjusted the information response mechanism of the device discovery service, strengthening protection of device information.- Fixed a data-handling issue in a firmware component on a specific model.- Strengthened input data validation in a device-pairing web function.- Improved data validation in the configuration file upload/sync function.- Improved how the account service restart process is handled.- Removed a non-essential internal function endpoint, strengthening overall access control.- Adjusted the debug file access mechanism, strengthening protection of internal data.- Strengthened data handling in the system logging function.We recommend upgrading to this version to maintain optimal protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23809 18 May 2026
Release notes — disclosure 0.35
Security Fixes- Enhanced system security by addressing an unsafe remote script execution mechanism in.- Improved system security by addressing a heap buffer overflow vulnerability during cache handling.We recommend upgrading to this version to ensure up-to-date protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23807 30 March 2026
Release notes — disclosure 0.38
Improvements:- Optimized Wi-Fi roaming stability for devices supporting 802.11k but not allowing 11v.- Improved Wi-Fi roaming compatibility and stability for iOS 26 devices.- Refined accessibility-related UI and interaction details.- Improved overall remote connection stability.Security Enhancements:- Strengthened input sanitization mechanism- Enhanced system API validation for stronger protection consistency.- Strengthened command handling and system resource access controls.- Improved system logging and security event recording mechanisms.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23763 27 October 2025
Release notes — disclosure 0.42
- Enhanced system stability.- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.- Implemented comprehensive validation and expanded command filtering in the web history API.- Fixed a privilege escalation vector in the IFTTT token exchange mechanism.- Strengthened input validation and directory handling in the VPN configuration upload interface.- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23749 3 September 2025
Release notes — disclosure 0.45
Important: After installing this firmware, we strongly recommend performing a factory-default reset to activate every new security adjustment.Security Enhancements- Password Policy Upgrade – Minimum of 10 characters, including at least one letter, one digit, and one special character; disallows consecutive identical characters; hardens defense against brute-force attacks.- HTTPS on 8443 – Management interface now served over TLS by default.- UPnP Disabled – Universal Plug and Play starts in the off state for reduced surface exposure.- AiCloud Authentication Hardening (CWE-287) – Added layered verification.- Authentication Logic Refactor – Removed redundant code paths for a lean sign-in flow.- Memory Safety Guard (CWE-476) – Introduced null-reference protections across critical services.- Enhanced IPsec Parameter Validation – The existing input checks have been hardened.- Data Exposure Mitigation (CWE-200) – Reinforced controls on sensitive pathways.- Detailed Audit Trails – Expanded logging within the authentication module.System Improvements- Connection Stability – Core algorithms refined for steadier links.- Scheduling Accuracy – Timed tasks execute reliably under PPPoE, PPTP and L2TP WAN modes.- Client List Maintenance – Resolved an issue that prevented offline devices from being removed from the client list
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23713 28 May 2025
Release notes — disclosure 0.31
Improved compatibility with certain IoT devices.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23712 14 March 2025
Release notes — disclosure 0.32
1.Enhanced input parameter handling techniques to improve data processing stability and system security.2.Enhance system access control mechanisms.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23708 4 March 2025
Release notes — disclosure 0.43
1. Fixed UI compatibility issues with the latest Chrome.2. Fixed client binding issues in Mesh scenarios.3. Fixed an issue where WAN and LAN status were displayed incorrectly.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23695 12 November 2024
Release notes — disclosure 0.58
1. Strengthened input validation and data processing workflows to further protect information security. 2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts. 3. Enhanced device security through improved buffer handling in connection features. 4. Refined data handling processes, ensuring secure and accurate information management. 5. Enhanced file access control mechanisms, promoting a more secure operating environment. 6. Strengthened certificate protection, providing enhanced data security.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23630 5 July 2023
Cites CVE-2020-12695, CVE-2020-28926, CVE-2022-3109, CVE-2022-3964, CVE-2022-48434, CVE-2023-0464, CVE-2023-28319, CVE-2023-28321, CVE-2023-28322, CVE-2023-28702, CVE-2023-28703, CVE-2023-35086, CVE-2023-35087, CVE-2023-35720
Release notes — disclosure 0.80
Bug fixes and functionality modifications:-Resolved the issue with login and password changes.-Resolved the IPSec VPN connection issues.-Resolved the Instant Guard connection issues.-Fixed the issue where Traffic Analyzer sometimes couldn't record data.-Fixed the time display issue for the preferred upgrade time in the Auto Firmware Upgrade function.-Enabled DynDNS and No-IP DDNS to use IPv6.-Fixed AiMesh preferred AP identification in site survey results.-Updated timezone list for Greenland, Mexico, and Iran.-Allowed WireGuard Server clients to access the Samba server.-Fixed memory leak issue.-Resolved the issue where the USB path is not displayed on the Media Server page in the AiMesh nodeSecurity updates:-Enabled and supported ECDSA certificates for Let's Encrypt.-Enhanced protection for credentials.-Enhanced protection for OTA firmware updates.-Fixed DoS vulnerabilities in firewall configuration pages. -Fixed DoS vulerabilities in httpd. -Fixed information disclosure vulnerability.-Fixed CVE-2023-28702 and CVE-2023-28703.-Fixed null pointer dereference vulnerabilities. -Fixed the cfg server vulnerability. -Fixed the vulnerability in the logmessage function CVE-2023-35086/ CVE-2023-35087. -Fixed lighttpd vulnerability, CVE-2023-35720.-Fixed several curl vulnerabilities including CVE-2023-28322, CVE-2023-28321, and CVE-2023-28319.-Fixed FFmpeg vulnerabilities, specifically CVE-2022-3964, CVE-2022-48434, and CVE-2022-3109.-Fixed openssl vulnerability, CVE-2023-0464.-Fixed ReadyMedia vulnerabilitym CVE-2020-28926.-Fixed UPnP vulnerability CVE-2020-12695.-Patched a command injection vulnerability to improve overall security.-Strengthened protection against SSH brute force attacks.
Archived page, fetched 29 September 2026
-
3.0.0.4.388.22525 16 February 2023
Cites CVE-2018-1160
Release notes — disclosure 1.00
Try more on ASUSWRT 2022 with new features at https://asus.click/ASUSWRT20221. Supported WireGuard VPN server and client.2. Supported VPN fusion. It can easily achieve VPN connection to network devices like Smart TV, Game consoles and without installing the VPN client software.3. Supported new devices connection notification.4. Supported connection diagnostic on the ASUS router app.5. Supported Instant Guard 2.0 which helps easily invite family or friends to join the VPN connection.6. Upgraded parental control and added reward, new scheduler for flexible setting7. Fixed USB icon issue in port status.8. Fixed HTTP response splitting vulnerability. Thanks to Efstratios Chatzoglou, University of the Aegean.9. Fixed status page HTML vulnerability. Thanks to David Ward.10. Fixed CVE-2018-1160. Thanks to Steven Sroba.11. Fixed cfg_server security issue.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.46061 21 January 2022
Release notes — disclosure 0.45
Security- Fixed string format stacks vulnerability- Fixed cross-site-scripting vulnerability- Fixed informational vulnerability.Thanks to Howard McGreehan.-Fixed SQL injection vulnerability-Fixed json file traversal vulnerability-Fixed plc/port file traversal vulnerability-Fixed stack overflow vulnerabilityThanks to HP of Cyber Kunlun Lab-Fixed authenticated stored XSS vulnerabilityThanks to Luke Walker – SmartDCC-Fixed LPD denial of service vulnerability-Fixed cfgserver heap overflow vulnerability-Fixed cfgserver denial of service vulnerabilityThanks to TianHe from BeFun Cyber Security Lab.Added more ISP profileDigi 1 - TMDigi 2 - TIMEDigi 3 - DigiDigi 4 - CTSDigi 5 - ALLODigi 6 - SACOFAMaxis - CTSMaxis - SACOFAMaxis - TNB/ALLOFixed AiMesh guest network issues.Fixed DDNS issues where the WAN IP is IPv6Fixed UI bugs in Administration --> feedback.Fixed time zone error.Improved the connection stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.45934 12 November 2021
Release notes — disclosure 0.48
1. Fixed Let's encrypt related bugs.2. Fixed httpd vulnerability3. Fixed stack overflow vulnerability4. Fixed DoS vulnerabilityThanks for the contribution of Fans0n、le3d1ng、Mwen、daliy yang from 360 Future Security Labs
Archived page, fetched 29 September 2026
-
3.0.0.4.386.45898 7 October 2021
Cites CVE-2015-8041, CVE-2016-2148, CVE-2016-4476, CVE-2016-6301, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, CVE-2018-1000120, CVE-2019-11555, CVE-2019-5481, CVE-2019-5482, CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497, CVE-2019-9498, CVE-2019-9499, CVE-2020-11810, CVE-2020-14305, CVE-2020-25643, CVE-2020-8169, CVE-2021-27803, CVE-2021-30004, CVE-2021-41435, CVE-2021-41436
Release notes — disclosure 0.95
This version includes several vulnerability patches.BusyBox- CVE-2016-2148- CVE-2016-6301- CVE-2018-1000517cURL- CVE-2020-8169- CVE-2019-5481- CVE-2019-5482- CVE-2018-1000120- CVE-2018- 1000300- CVE-2018-16839Lighttpd- CVE-2018-19052Linux- CVE-2020-14305- CVE-2020-25643- CVE-2019-19052lldpd- CVE-2020-27827Avahi- CVE-2017-6519hostapd- CVE-2021-30004- CVE-2019-16275OpenVPN- CVE-2020-11810- CVE-2020-15078wpa- CVE-2021-30004- CVE-2021-27803- CVE-2019-11555- CVE-2019-9499- CVE-2019-9498- CVE-2019-9497- CVE-2019-9496- CVE-2019-9495- CVE-2019-9494- CVE-2017-13086- CVE-2017-13084- CVE-2017-13082- CVE-2016-4476- CVE-2015-8041-Fixed DoS vulnerability from spoofed sae authentication frame. Thanks to Efstratios Chatzoglou, University of the Aegean, Georgios Kambourakis, European Commission at the European Joint Research Centre, and Constantinos Kolias, University of Idaho.-Fixed envrams exposed issue. Thanks to Quentin Kaiser from IoT Inspector Research Lab contribution.-Fixed AiMesh web page multi-language issues.-Fixed Stored XSS vulnerability.-Fixed CVE-2021-41435, CVE-2021-41436.Thanks to Efstratios Chatzoglou, University of the AegeanGeorgios Kambourakis, European Commission at the European Joint Research CentreConstantinos Kolias, University of Idaho.-Fixed Stack overflow vulnerability. Thanks to Jixing Wang (@chamd5) contribution.-Fixed information disclosure vulnerability .Thanks to CataLpa from DBappSecurity Co.,Ltd Hatlab and 360 Alpha Lab contribution.Supported v6plus
Archived page, fetched 29 September 2026
-
3.0.0.4.386.44695 8 September 2021
Release notes — disclosure 0.33
Bug Fixes:- Fix 5GHz WiFi abnormal issue.- Fix parental control abnormal issue with app. (Need to work with iOS v.1.0.0.6.46 Android 1.0.0.6.45 and later versions)
Archived page, fetched 29 September 2026
-
3.0.0.4.386.43084 3 June 2021
Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2020-25687
Release notes — disclosure 0.73
1.Fixed the FragAttack vulnerability.2.Fixed DoS vulnerability. Thanks for Tsinghua University NISL's contribution.3.Improved system stability.4.Fixed GUI bugs.5.Security Fixed: CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686
Archived page, fetched 29 September 2026
-
9.0.0.4.386.41994 3 February 2021
Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25687
Release notes — disclosure 0.74
Security Fixed: Fixed CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686Please be noted this is a quick fix beta version for DNSmasq vulnerabilities. Refer to "Method 2: Update Manually" in https://www.asus.com/support/FAQ/1008000 to update this firmware.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.41712 25 January 2021
Release notes — disclosure 0.65
[Known issue] If your RT-AX92U firmware was 3.0.0.4.386.41535, please use ASUS Router App or the firmware check button in Web GUI to upgrade firmware. Manually upload the firmware from 386.41535 to 386.41712 might not be successful. Other versions before 386.41535 do not have this issue. 1. AiMesh 2.0 - System optimization: one click in AiMesh to optimize the topology - System Ethernet backhaul mode, all nodes will only connect by ethernet, and all bands can release for wireless clients. - System factory default and reboot. - Client device reconnect, make the device offline and online again. - Client device binding to specific AP. - Guest WiFi on all Mesh nodes (all node need to upgrade to 3.0.0.4.386 firmware) - Access nodes USB application. Connection priority and Ethernet backhaul mode introduction https://www.asus.com/support/FAQ/1044184 How to setup ASUS AiMesh or ZenWiFi Mesh Ethernet backhaul under different conditions https://www.asus.com/support/FAQ/1044151/ 2. New Family interface in ASUS router App. ASUS Router App for iOS must greater than iOS v1.0.0.5.75 Android version greater than v1.0.0.5.74 3. The unit of the WiFi time scheduler goes to 1 minute. 4. Support IPSec IKE v1 and IKE v2, and you can use the Windows 10 native VPN client program to connect to the router's IPSec VPN server. The Windows 10 new FAQ is in https://www.asus.com/support/FAQ/1033576 5. 2.4 and 5G settings on the network map could modify in the same tab. 6. Captcha for login can be disabled in the administration -> system. 7. Printer server port can be disabled on the USB app page. 8. Clients who connect to the guest network can be viewed in the network map -->view list --> interface 9. Fixed Let's Encrypt issue. 10. Added IPTV supports for a specific region. 11. Fixed the throughput issue.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.40451 22 October 2020
Release notes — disclosure 0.65
New features1. AiMesh 2.0- System optimization: one click in AiMesh to optimize the topology- System Ethernet backhaul mode, all nodes will only connect by ethernet, all bands will be released for wireless clients.- System factory default and reboot.- Client device reconnect, make the device to offline and online again.- Client device binding to specific AP.- Guest WiFi on all Mesh nodes (all node need to upgrade to 3.0.0.4.386 firmware)- Access nodes USB application.Connection priority and Ethernet backhaul mode introduction https://www.asus.com/support/FAQ/1044184How to setup ASUS AiMesh or ZenWiFi Mesh Ethernet backhaul under different conditionshttps://www.asus.com/support/FAQ/1044151/2. New Family interface in ASUS router App. ASUS Router App for iOS must greater or equal to iOS v1.0.0.5.75 Android version greater or equal to v1.0.0.5.743. The unit of the WiFi time scheduler goes to 1 minute.4. Support IPSec IKE v1 and IKE v2, and you can use the Windows 10 native VPN client program to connect to the router's IPSec VPN server. The Windows 10 new FAQ is in https://www.asus.com/support/FAQ/10335765. 2.4 and 5G on the network map could be configured in the same tab.6. Captcha for login can be disabled in administration -> system.7. Printer server port can be disabled on the USB app page.8. Clients which connect to the guest network can be viewed in the network map -->view list --> interface
Archived page, fetched 29 September 2026
-
3.0.0.4.384.9177 20 May 2020
Release notes — disclosure 0.47
- Enhanced AiMesh connection stability - Modified the Telnet/SSH setting UI message - Fixed login bugs. - Support router certificate export. After import the certificate to the computer you will not see the warning message when login with https. Please refer to https://www.asus.com/us/support/FAQ/1034294/ * By updating to this version, it's recommended to factory reset your RT-AX92U.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.8697 30 March 2020
Release notes — disclosure 0.55
1. Update Adaptive QoS categories: Help you to prioritize the mission-critical applications Those people who work-from-home & learn-from-home will greatly benefit from this new feature with optimized streaming experiences. New Supported Categories & Apps: - Video conferencing, including Microsoft Teams®, ZOOM®, Skype®, Google Hangouts®, BlueJeans®- Online learning, including Khan academy®, Udemy®, Coursera®, TED®, VIPKiD®, 51Talk®, XDF®, Xueersi®- Streaming, including YouTube®, Netflix®, HBO NOW®, Amazon Prime Video®, Disney+®, ESPN®, MLB.com®, iQIY®- Indoor training, including Zwift®, Peloton®, Onelap® Stay tuned and more apps are coming to the list soon! 2. Support Mobile Game Mode and upgrade your RT-AX92U to a Gaming Mesh - One-click prioritizing your mobile device to the highest and ensure you the best mobile gaming experiences. - Install/Update ASUS Router App (Android supports later than 1.0.0.5.44; iOS supports later than 1.0.0.5.41)
Archived page, fetched 29 September 2026
-
3.0.0.4.384.8681 19 March 2020
Cites CVE-2019-15126
Release notes — disclosure 0.66
- Fixed CVE-2019-15126 (Kr00k) vulnerability. - Improved system stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.7977 22 January 2020
Release notes — disclosure 0.34
- Enhanced the Wi-Fi 6 performance with Apple® iPhone11, Samsung® S10.- Supported WPA3.- Supported OFDMA.- Supported 802.11k and 802.11v.- Fixed Let's encrypt register related bugs.- Fixed openVPN related bugs.- Improved system stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.6437 6 November 2019
Release notes — disclosure 0.05
- Improve wireless stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.6436 23 September 2019
Release notes — disclosure 0.49
Security fix - Fixed a DDoS vulnerability. Thanks for Altin Thartori's contribution. Bug fix - Fixed web control interface login problem. - Fixed Network map clist list issues. - Fixed block internet access problem when clients connected to AiMesh node - Fixed Samba server compatibility issue. - Fixed OpenVPN related bugs. - Fixed schedule reboot bugs. - Improved AiMesh compatibility. - Improved system stability. - Fixed User interface related bugs.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.6287 19 July 2019
Release notes — disclosure 0.06
-Stability improvement - Fixed PPPoE issues
Archived page, fetched 29 September 2026
-
3.0.0.4.384.6204 18 June 2019
Release notes — disclosure 0.31
- Optimize backhaul connection- Fix reboot error
Archived page, fetched 29 September 2026
-
3.0.0.4.384.6121 28 May 2019
Release notes — disclosure 0.32
- Fix roaming related issue.- Fix internet connection stability issues.- Improves combatibility with wifi clients.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.6063 8 May 2019
Release notes — disclosure 0.30
- Add WAN aggregation
Archived page, fetched 29 September 2026
-
3.0.0.4.384.5979 30 April 2019
Release notes — disclosure 0.31
The first version of firmware for RT-AX92U
Archived page, fetched 29 September 2026
Evidence
One archived page sits behind this record, the earliest read on 2 August 2026. Everything above was read from it, and each is kept byte for byte so it can be checked after the vendor edits the original.
Identifiers: marketing_name RT-AX92U
Judged by lifecycle-1 on 30 September 2026.
How these verdicts are computed.