ZenWiFi ET8
Actively updated well evidenced
firmware is arriving about as often as it always has
57 days since the last release against a median gap of 132 (0.4x)
- Last firmware
- 4 August 2026 (2 months ago)
- Releases seen
- 12
- Update rhythm
- about every 4 months
- Support observed
- ≥5 years
- Vendor's promise
- no support period we can evaluate
- Patch latency
- not measurable — its changelogs name no CVE ids
Which one do I have?
ASUS ships this model in more than one hardware revision, and they do not share firmware. The revision is printed on the label on the underside, usually after the model — Ver 1.0, V4.6. Getting it wrong is the easiest way to read the wrong answer here.
- ZenWiFi ET8 v2 Actively updated 6 releases
Firmware history
-
3.0.0.4.388_25264 4 August 2026
Release notes — disclosure 0.45
Security Fixes- Strengthened data handling in Networks configuration functions.- Improved data validation in Networks rule list processing.- Fixed a data-handling issue in the DNS query caching component.- Strengthened verification when a software component downloads - external resources, improving connection security.- Adjusted the information response mechanism of the device discovery service, strengthening protection of device information.- Fixed a data-handling issue in a firmware component on a specific model.- Improved data-display handling in a web function to enhance browsing security.- Strengthened input data validation in a device-pairing web function.- Improved data validation in the configuration file upload/sync function.- Improved how the account service restart process is handled.- Removed a non-essential internal function endpoint, strengthening overall access control.- Adjusted the debug file access mechanism, strengthening protection of internal data.- Strengthened data handling in the system logging function.We recommend upgrading to this version to maintain optimal protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_25232 19 May 2026
Release notes — disclosure 0.45
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.Security Fixes- Enhanced DNS Handling: Improved DNS name processing to address potential memory issues that could occur in rare cases during name format conversion, enhancing system security and robustness.- Strengthened Execution Module Safeguards: Improved protections for system execution modules to reduce the risk of unauthorized substitution during specific processes.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_25186 28 October 2025
Release notes — disclosure 0.50
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.- Enhanced system stability.- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.- Addressed multiple security weaknesses in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.- Implemented comprehensive validation and expanded command filtering in the web history API.- Fixed a privilege escalation vector in the IFTTT token exchange mechanism- Strengthened input validation and directory handling in the VPN configuration upload interface.- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_25174 9 September 2025
Release notes — disclosure 0.50
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.Important: After installing this firmware, we strongly recommend performing a factory-default reset to activate every new security adjustment.Security Enhancements- Password Policy Upgrade – Minimum of 10 characters, including at least one letter, one digit, and one special character; disallows consecutive identical characters; hardens defense against brute-force attacks.- HTTPS on 8443 – Management interface now served over TLS by default.- UPnP Disabled – Universal Plug and Play starts in the off state for reduced surface exposure.- AiCloud Authentication Hardening (CWE-287) – Added layered verification.- Authentication Logic Refactor – Removed redundant code paths for a lean sign-in flow.- Memory Safety Guard (CWE-476) – Introduced null-reference protections across critical services.- Enhanced IPsec Parameter Validation – The existing input checks have been hardened.- Data Exposure Mitigation (CWE-200) – Reinforced controls on sensitive pathways.- Detailed Audit Trails – Expanded logging within the authentication module.System Improvements- Connection Stability – Core algorithms refined for steadier links.- Scheduling Accuracy – Timed tasks execute reliably under PPPoE, PPTP and L2TP WAN modes.- Client List Maintenance – Resolved an issue that prevented offline devices from being removed from the client list
Archived page, fetched 29 September 2026
-
3.0.0.4.388_25139 8 May 2025
Release notes — disclosure 0.40
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.Improved compatibility with certain IoT devices.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_25138 20 March 2025
Release notes — disclosure 0.58
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.1. Fixed the UI issue in Chrome.2. Fixed client binding issues in Mesh scenarios.3. Enhanced input parameter handling techniques to improve data processing stability and system security.4. Enhance system access control mechanisms.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_25124 8 November 2024
Release notes — disclosure 0.62
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.1. Strengthened input validation and data processing workflows to further protect information security.2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.3. Enhanced device security through improved buffer handling in connection features.4. Refined data handling processes, ensuring secure and accurate information management.5. Enhanced file access control mechanisms, promoting a more secure operating environment.6. Strengthened certificate protection, providing enhanced data security.
Archived page, fetched 29 September 2026
-
3.0.0.4_388_25112 23 September 2024
Release notes — disclosure 0.61
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.1. Optimized memory management mechanisms, improving system efficiency and stability.2. Strengthened input validation and data processing workflows, further protecting your information security.3. Improved web rendering engine, enhancing browsing experience and security.4. Enhanced security of system command processing to guard against potential malicious operations.5. Perfected JavaScript-related security mechanisms, offering a more secure web interaction environment.
Archived page, fetched 29 September 2026
-
3.0.0.4.388_23759 3 August 2023
Cites CVE-2020-12695, CVE-2020-28926, CVE-2022-3109, CVE-2022-3964, CVE-2022-4687125, CVE-2022-48434, CVE-2023-0464, CVE-2023-28319, CVE-2023-28321, CVE-2023-28322, CVE-2023-28702, CVE-2023-28703, CVE-2023-34358, CVE-2023-34359, CVE-2023-34360, CVE-2023-35086, CVE-2023-35087, CVE-2023-35720
Release notes — disclosure 1.00
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.New features:1.Plug, Share & Surf: Turn Your ET8 into a 4G/5G Hotspot. Unleash the power of 4G and 5G connectivity without the need for a new router. With your ASUS router and smartphone, you can access high-speed internet instantly. It's as simple as plugging in your phone and sharing its network. Please refer to https://asus.click/AutobackupWAN2.DDNS transfer allows you to transfer your ASUS DDNS hostname from your original router to the new one. Please refer to https://asus.click/ASUSDDNS3.Built-in Surfshark in VPN Fusion allows you to surf the internet anonymously and securely from anywhere by encrypting connections. Please refer to https://asus.click/SurfsharkVPN4.Supported WireGuard VPN server and client.5.Supported VPN fusion. It can easily achieve VPN connection to network devices like Smart TV, Game consoles and without installing the VPN client software.6.Supported new devices connection notification.7.Supported connection diagnostic on the ASUS router app.8.Supported Instant Guard 2.0 which helps easily invite family or friends to join the VPN connection.9.Upgraded parental control and added reward, new scheduler for flexible settingSecurity updates:1.Enabled and supported ECDSA certificates for Let's Encrypt.2.Allowed binding DDNS to a user's account to reduce the risk of MITM attacks3.Enhanced protection for credentials.4.Enhanced protection for OTA firmware updates.5.Fixed CVE-2023-34359,CVE-2023-34358 Unauthenticated Denial of Service6.Fixed CVE-2023-34360 Stored XSS7.Fixed DoS vulnerabilities in firewall configuration pages. 8.Fixed DoS vulerabilities in httpd. 9.Fixed information disclosure vulnerability.10.Fixed CVE-2023-28702 and CVE-2023-28703.11.Fixed null pointer dereference vulnerabilities. 12.Fixed the cfg server vulnerability. 13.Fixed the vulnerability in the logmessage function CVE-2023-35086/ CVE-2023-35087. 14.Fixed lighttpd vulnerability, CVE-2023-35720.15.Fixed several curl vulnerabilities including CVE-2023-28322, CVE-2023-28321, and CVE-2023-28319.16.Fixed FFmpeg vulnerabilities, specifically CVE-2022-3964, CVE-2022-48434, and CVE-2022-3109.17.Fixed openssl vulnerability, CVE-2023-0464.18.Fixed ReadyMedia vulnerabilitym CVE-2020-28926.19.Fixed UPnP vulnerability CVE-2020-12695.20.Patched a command injection vulnerability to improve overall security.21.Strengthened protection against SSH brute force attacks.22.Fixed the cfg server vulnerability.23.Fixed the vulnerability in the logmessage function.24..Fixed CVE-2022-4687125.Fixed Client DOM Stored XSS.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.49873 4 August 2022
Cites CVE-2018-1160, CVE-2021-34174, CVE-2022-07782, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-263766
Release notes — disclosure 0.98
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.1. Fixed OpenSSL CVE-2022-07782. Fixed CVE-2018-1160, Thanks to Steven Sroba3. Added more security measures to block malware.4. Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.5. Fixed CVE-2021-34174, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-263766. Improved system stability.7. Fixed anomalous 802.11 frame issues.Thanks to Kari Hulkko and Tuomo Untinen from The Synopsys Cybersecurity Research Center (CyRC). Issue was found by using Defensics Fuzz Testing Tool.8. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.9. Supported Safe Browsing in the router app to filter explicit content from search results. You can set it in the router app --> Devices or Family.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.46061 11 January 2022
Release notes — disclosure 0.47
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.Security- Fixed string format stacks vulnerability- Fixed cross-site-scripting vulnerability- Fixed informational vulnerability.Thanks to Howard McGreehan.-Fixed SQL injection vulnerability-Fixed json file traversal vulnerability-Fixed plc/port file traversal vulnerability-Fixed stack overflow vulnerabilityThanks to HP of Cyber Kunlun Lab-Fixed authenticated stored XSS vulnerabilityThanks to Luke Walker – SmartDCC-Fixed LPD denial of service vulnerability-Fixed cfgserver heap overflow vulnerability-Fixed cfgserver denial of service vulnerabilityThanks to TianHe from BeFun Cyber Security Lab.Added more ISP profile Digi 1 - TMDigi 2 - TIMEDigi 3 - DigiDigi 4 - CTSDigi 5 - ALLODigi 6 - SACOFAMaxis - CTSMaxis - SACOFAMaxis - TNB/ALLOFixed AiMesh guest network issues.Fixed DDNS issues where the WAN IP is IPv6Fixed UI bugs in Administration --> feedback. Fixed time zone error.Improved the connection stability.
Archived page, fetched 29 September 2026
-
3.0.0.4.386.43981 11 June 2021
Release notes — disclosure 0.40
This version of firmware is only applicable to ZenWiFi ET8 of HW Ver: 1.0, please check the product label before utilizing. You can check the hardware version from the product SN label or box label.Initial release
Archived page, fetched 29 September 2026
Evidence
One archived page sits behind this record, the earliest read on 2 August 2026. Everything above was read from it, and each is kept byte for byte so it can be checked after the vendor edits the original.
Identifiers: marketing_name ZenWiFi ET8
Judged by lifecycle-1 on 30 September 2026.
How these verdicts are computed.