TUF-AX3000
Slowing down well evidenced
updates are coming less often than this product's own history
145 days since the last release against a median gap of 71 (2.0x)
- Last firmware
- 8 May 2026 (5 months ago)
- Releases seen
- 22
- Update rhythm
- about every 2 months
- Support observed
- ≥6 years
- Vendor's promise
- no support period we can evaluate
- Patch latency
- not measurable — its changelogs name no CVE ids
Which one do I have?
ASUS ships this model in more than one hardware revision, and they do not share firmware. The revision is printed on the label on the underside, usually after the model — Ver 1.0, V4.6. Getting it wrong is the easiest way to read the wrong answer here.
- TUF-AX3000 v2 Actively updated 15 releases
Firmware history
-
3.0.0.4.388_22725 8 May 2026
Release notes — disclosure 0.35
Security Fixes- Enhanced system security by addressing an unsafe remote script execution mechanism in.- Improved system security by addressing a heap buffer overflow vulnerability during cache handling.We recommend upgrading to this version to ensure up-to-date protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_22723 23 April 2026
Release notes — disclosure 0.38
Improvements:- Optimized Wi-Fi roaming stability for devices supporting 802.11k but not allowing 11v.- Improved Wi-Fi roaming compatibility and stability for iOS 26 devices.- Refined accessibility-related UI and interaction details.- Improved overall remote connection stability.Security Enhancements:- Strengthened input sanitization mechanism- Enhanced system API validation for stronger protection consistency.- Strengthened command handling and system resource access controls.- Improved system logging and security event recording mechanisms.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_22675 28 October 2025
Release notes — disclosure 0.42
- Enhanced system stability.- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.- Implemented comprehensive validation and expanded command filtering in the web history API.G1- Fixed a privilege escalation vector in the IFTTT token exchange mechanism- Strengthened input validation and directory handling in the VPN configuration upload interface.- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_22612 14 May 2025
Release notes — disclosure 0.31
Improved compatibility with certain IoT devices.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_22611 18 March 2025
Release notes — disclosure 0.32
1.Enhanced input parameter handling techniques to improve data processing stability and system security.2.Enhance system access control mechanisms.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_22607 7 February 2025
Release notes — disclosure 0.37
1. Fixed UI compatibility issues with the latest Chrome.2. Fixed client binding issues in Mesh scenarios.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_22599 12 November 2024
Release notes — disclosure 0.58
1. Strengthened input validation and data processing workflows to further protect information security.2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.3. Enhanced device security through improved buffer handling in connection features.4. Refined data handling processes, ensuring secure and accurate information management.5. Enhanced file access control mechanisms, promoting a more secure operating environment.6. Strengthened certificate protection, providing enhanced data security.
Archived page, fetched 29 September 2026
-
3.0.0.4.388.22525 14 February 2023
Cites CVE-2022-468712
Release notes — disclosure 0.70
1.Fixed CVE-2022-468712.Fixed Client DOM Stored XSS.3.Improved AiMesh backhaul stability.4.Fixed AiMesh topology UI bugs.5.Fixed the reboot issue when assigning specific clients in VPN fusion.6.Fixed the VPN fusion bug when importing the Surfshark WireGuard conf file.7.Fixed network map bugs.
Archived page, fetched 29 September 2026
-
3.0.0.4.388.22237 4 January 2023
Cites CVE-2018-1160
Release notes — disclosure 0.98
1. Supported WireGuard VPN server and client.2. Supported VPN fusion. It can easily achieve VPN connection to network devices like Smart TV, Game consoles and without installing the VPN client software.3. Supported new devices connection notification.4. Supported connection diagnostic on the ASUS router app.5. Supported Instant Guard 2.0 which helps easily invite family or friends to join the VPN connection.6. Upgraded parental control and added reward, new scheduler for flexible setting7. Fixed HTTP response splitting vulnerability. Thanks to Efstratios Chatzoglou, University of the Aegean.8. Fixed status page HTML vulnerability. Thanks to David Ward.9. Fixed CVE-2018-1160. Thanks to Steven Sroba.10. Fixed cfg_server security issue.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.49780 26 July 2022
Cites CVE-2022-0778, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-263762
Release notes — disclosure 0.84
1. Fixed CVE-2022-0778,CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-263762. Fixed Stored XSS vulnerability. 3. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.4. Improved system stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.48377 8 April 2022
Cites CVE-2021-341743, CVE-2022-07782, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-255976
Release notes — disclosure 0.95
1. Fixed OpenSSL CVE-2022-07782. Fixed CVE-2021-341743. Added more security measures to block malware.4. Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.5. Fixed CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-255976. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.7. Fixed anomalous 802.11 frame issues. Thanks to Kari Hulkko and Tuomo Untinen from The Synopsys Cybersecurity Research Center (CyRC). Issue was found by using Defensics Fuzz Testing Tool.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.46061 14 January 2022
Release notes — disclosure 0.37
Security- Fixed string format stacks vulnerability- Fixed cross-site-scripting vulnerability- Fixed informational vulnerability.Thanks to Howard McGreehan.-Fixed SQL injection vulnerability-Fixed json file traversal vulnerability-Fixed plc/port file traversal vulnerability-Fixed stack overflow vulnerabilityThanks to HP of Cyber Kunlun Lab-Fixed authenticated stored XSS vulnerabilityThanks to Luke Walker – SmartDCC-Fixed LPD denial of service vulnerability-Fixed cfgserver heap overflow vulnerability-Fixed cfgserver denial of service vulnerabilityThanks to TianHe from BeFun Cyber Security Lab.Added more ISP profile Digi 1 - TMDigi 2 - TIMEDigi 3 - DigiDigi 4 - CTSDigi 5 - ALLODigi 6 - SACOFAMaxis - CTSMaxis - SACOFAMaxis - TNB/ALLOFixed AiMesh guest network issues.Fixed DDNS issues where the WAN IP is IPv6Fixed UI bugs in Administration --> feedback. Fixed time zone error.Improved the connection stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.45934 11 November 2021
Release notes — disclosure 0.48
1. Fixed Let's encrypt related bugs.2. Fixed httpd vulnerability3. Fixed stack overflow vulnerability4. Fixed DoS vulnerabilityThanks for the contribution of Fans0n、le3d1ng、Mwen、daliy yang from 360 Future Security Labs
Archived page, fetched 29 September 2026
-
3.0.0.4.386.45898 13 October 2021
Cites CVE-2015-8041, CVE-2016-2148, CVE-2016-4476, CVE-2016-6301, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, CVE-2018-1000120, CVE-2019-11555, CVE-2019-5481, CVE-2019-5482, CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497, CVE-2019-9498, CVE-2019-9499, CVE-2020-11810, CVE-2020-14305, CVE-2020-25643, CVE-2020-8169, CVE-2021-27803, CVE-2021-30004, CVE-2021-41435, CVE-2021-41436
Release notes — disclosure 0.95
This version includes several vulnerability patches.BusyBox- CVE-2016-2148- CVE-2016-6301- CVE-2018-1000517cURL- CVE-2020-8169- CVE-2019-5481- CVE-2019-5482- CVE-2018-1000120- CVE-2018- 1000300- CVE-2018-16839Lighttpd- CVE-2018-19052Linux- CVE-2020-14305- CVE-2020-25643- CVE-2019-19052lldpd- CVE-2020-27827Avahi- CVE-2017-6519hostapd- CVE-2021-30004- CVE-2019-16275OpenVPN- CVE-2020-11810- CVE-2020-15078wpa- CVE-2021-30004- CVE-2021-27803- CVE-2019-11555- CVE-2019-9499- CVE-2019-9498- CVE-2019-9497- CVE-2019-9496- CVE-2019-9495- CVE-2019-9494- CVE-2017-13086- CVE-2017-13084- CVE-2017-13082- CVE-2016-4476- CVE-2015-8041-Fixed DoS vulnerability from spoofed sae authentication frame. Thanks to Efstratios Chatzoglou, University of the Aegean, Georgios Kambourakis, European Commission at the European Joint Research Centre, and Constantinos Kolias, University of Idaho.-Fixed envrams exposed issue. Thanks to Quentin Kaiser from IoT Inspector Research Lab contribution.-Fixed AiMesh web page multi-language issues.-Fixed Stored XSS vulnerability.-Fixed CVE-2021-41435, CVE-2021-41436.Thanks to Efstratios Chatzoglou, University of the AegeanGeorgios Kambourakis, European Commission at the European Joint Research CentreConstantinos Kolias, University of Idaho.-Fixed Stack overflow vulnerability. Thanks to Jixing Wang (@chamd5) contribution.-Fixed information disclosure vulnerability .Thanks to CataLpa from DBappSecurity Co.,Ltd Hatlab and Yao Chen(@ysmilec) of 360 Alpha Lab contribution.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.43588 28 July 2021
Release notes — disclosure 0.51
1. Fix AiMesh issues.2. Improve system stability.3. Fix WAN DNS setting cannot setup LAN side pihole server.4. Modify few IPTV settings.5. Add JPNE v6plus support. 6. Add Google assistant support. (ASUS Router app version later than 1.0.0.6.38)
Archived page, fetched 29 September 2026
-
3.0.0.4.386.43406 9 June 2021
Release notes — disclosure 0.23
1. Improve system stability.2. GUI bug fix.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.43241 26 May 2021
Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2020-25687
Release notes — disclosure 0.73
1.Fixed the FragAttack vulnerability.2.Fixed DoS vulnerability. Thanks for Tsinghua University NISL's contribution.3.Improved system stability.4.Fixed GUI bugs.5.Security Fixed: CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686
Archived page, fetched 29 September 2026
-
9.0.0.4.386.41994 1 February 2021
Cites CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25687
Release notes — disclosure 0.74
Security Fixed: Fixed CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686Please be noted this is a quick fix beta version for DNSmasq vulnerabilities. Refer to "Method 2: Update Manually" in https://www.asus.com/support/FAQ/1008000 to update this firmware.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.41700 20 January 2021
Release notes — disclosure 0.65
1. AiMesh 2.0- System optimization: one click in AiMesh to optimize the topology- System Ethernet backhaul mode, all nodes will only connect by ethernet, all bands will be released for wireless clients.- System factory default and reboot.- Client device reconnect, make the device to offline and online again.- Client device binding to specific AP.- Guest WiFi on all Mesh nodes (all node need to upgrade to 3.0.0.4.386 firmware)- Access nodes USB application.Connection priority and Ethernet backhaul mode introductionhttps://www.asus.com/support/FAQ/1044184How to setup ASUS AiMesh or ZenWiFi Mesh Ethernet backhaul under different conditionshttps://www.asus.com/support/FAQ/1044151/2. New Family interface in ASUS router App.ASUS Router App for iOS must greater or equal to iOS v1.0.0.5.75Android version greater or equal to v1.0.0.5.743. The unit of the WiFi time scheduler goes to 1 minute.4. Support IPSec IKE v1 and IKE v2, and you can use the Windows 10 native VPN client program to connect to the router's IPSec VPN server. The Windows 10 new FAQ is in https://www.asus.com/support/FAQ/10335765. 2.4 and 5G on the network map could be configured in the same tab.6. Captcha for login can be disabled in administration -> system.7. Printer server port can be disabled on the USB app page.8. Clients which connect to the guest network can be viewed in the network map -->view list --> interface9. Fixed Let's Encrypt not working properly.10. Added IPTV supports for specific region.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.10177 9 December 2020
Release notes — disclosure 0.33
- Fix IPTV issues for specific regions.- Update language support list for specific regions.- Improve system stability.- Minor GUI bug fixes.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.9923 16 October 2020
Release notes — disclosure 0.05
- Improve system stability
Archived page, fetched 29 September 2026
-
3.0.0.4.384.9190 22 May 2020
Release notes — disclosure 0.06
- Improve system stability.- Fix AiCloud related issue.
Archived page, fetched 29 September 2026
-
3.0.0.4.384.8563 12 March 2020
Cites CVE-2019-15126
Release notes — disclosure 0.68
- Fixed bandwidth limiter issues. - Fixed setup wizard GUI bugs. - Supports 2.4G/5GHz uplink OFDMA and 802.11ax MU-MIMO. - Security Fix: CVE-2019-15126
Archived page, fetched 29 September 2026
Evidence
One archived page sits behind this record, the earliest read on 2 August 2026. Everything above was read from it, and each is kept byte for byte so it can be checked after the vendor edits the original.
Identifiers: marketing_name TUF-AX3000
Judged by lifecycle-1 on 30 September 2026.
How these verdicts are computed.