Upgrade Warranty: Here.
* Please note that the availability of the Premium Care product lines might differ by country.
- Driver & Tools
- FAQ
- Manual & Document
- Warranty
- More Service
BIOS & FIRMWARE
- Driver & Tools
- BIOS & FIRMWARE
This update includes a required change for the Speedtest service. If Speedtest is supported on your model, you must install this update to continue using it. Please refer to Speedtest Service Announcement for details.
https://www.asus.com/support/faq/1057454/
Supports Surfshark VPN account login for a smoother user experience. (Supported model only)
Security Fixes
Web management interface: Strengthened data handling for the connected device list and added stricter content checks when importing configuration profiles.
Network speed test service: Added allowlist validation for service command parameters, so that only expected values are accepted.
AiCloud: Strengthened the data handling mechanism for the network neighborhood host list.
AiCloud: Improved how share link identifiers are generated, and adjusted the file and disk information query process.
AiCloud: Strengthened authentication and path validation for remote file access.
System protection service: Adjusted address parameter validation and event logging, strengthening access control between local services.
Certificate import process: Adjusted file handling and password passing, with stricter parameter validation.
Third-party account authorization: Narrowed the recipients of authorization data to better protect authorization information.
Web management interface: Adjusted the output handling of feedback content.
Notification service: Added identity verification for local connection sources and tightened the related file permission settings.
Mobile device connection authorization: Added a device matching check to strengthen the access token issuance process.
Device discovery service: Removed a non-essential internal function endpoint to strengthen overall access control.
AiMesh: Adjusted data access protection during the node joining process, improving system stability while connections are being established.
System temporary directory: Adjusted the default permissions applied at creation time to narrow local file access.
Network diagnostic data query: Strengthened value range checks for time interval parameters.
Network diagnostic data query: Added allowlist validation for query fields.
Internal data query: Improved field matching logic and optimized the memory release process under error conditions.
Time synchronization settings: Strengthened parameter validation for the server name.
File upload handling: Fixed an issue where certain input formats could cause the web management service to become unresponsive.
Wireless channel selection tool: Adjusted the handling of command parameters to prevent unintended command execution.
Certificate upload: Added a pre-check of archive contents to prevent files from being written to unintended locations.
System configuration file generation: Strengthened parameter content checks to prevent abnormal configuration values from affecting network service settings.
VPN and account authentication services: Adjusted the handling of connection settings and account data, with stricter parameter validation.
We recommend updating to this version to maintain optimal protection.
New Features
- LED Lighting Scheduler: Added scheduling support for LED lighting, so lighting can turn on or off automatically on a custom schedule. (Available only on supported models.)
- New Time Zone Options: Added "Vancouver, Whitehorse (PST7)" and "Edmonton, Yellowknife (MST6)" time zone options for Canada.
Bug Fixes and Enhancements
- Improved MAC address display logic on the WDS (wireless bridge) page, fixing cases where the band name and its MAC address were shown incorrectly.
- Fixed an issue where Client List sorting could stop working under certain conditions, and removed a duplicate wired device card in the "By Interface" view.
- Optimized the IPv6 address design for Networks.
- Improved handling of unstable network cables.
- Improved stability during the AiMesh node setup process.
- Fixed an issue where a physical LAN port could disappear after the setup process when using the automatic WAN type detection mechanism.
- Improved AP Isolation synchronization for Networks profiles that don't use a dedicated subnet.
- Strengthened firewall rule configuration for UPnP, improving port-forwarding stability and firewall rule restoration reliability.
- Improved Network stylesheet loading reliability.
- Fixed an issue where the URL-forwarding utility could become unresponsive after an internal network component update.
Security Fixes
- Strengthened data handling in Networks configuration functions.
- Improved data validation in Networks rule list processing.
- Fixed a data-handling issue in the DNS query caching component.
- Strengthened verification when a software component downloads external resources, improving connection security.
- Adjusted the information response mechanism of the device discovery service, strengthening protection of device information.
- Fixed a data-handling issue in a firmware component on a specific model.
- Improved data-display handling in a web function to enhance browsing security.
- Strengthened input data validation in a device-pairing web function.
- Improved data validation in the configuration file upload/sync function.
- Improved how the account service restart process is handled.
- Removed a non-essential internal function endpoint, strengthening overall access control.
- Adjusted the debug file access mechanism, strengthening protection of internal data.
- Strengthened data handling in the system logging function.
We recommend upgrading to this version to maintain optimal protection.
Security Fixes
- Enhanced system security by addressing an unsafe remote script execution mechanism in.
- Improved system security by addressing a heap buffer overflow vulnerability during cache handling.
We recommend upgrading to this version to ensure up-to-date protection.
Improvements:
Optimized Wi-Fi roaming stability for devices supporting 802.11k but not allowing 11v.
Improved Wi-Fi roaming compatibility and stability for iOS 26 devices.
Refined accessibility-related UI and interaction details.
Improved overall remote connection stability.
Improved system behavior when using System Diagnostic on feedback page.
Bug Fixes:
Fixed incorrect connection status display for certain Wi-Fi devices.
Fixed a system issue that caused AiCloud features to appear on unsupported models.
Security Enhancements:
Strengthened input sanitization mechanism
Enhanced system API validation for stronger protection consistency.
Strengthened command handling and system resource access controls.
Improved system logging and security event recording mechanisms.
- Enhanced system stability.
- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.
- Addressed multiple security weaknesses in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.
- Implemented comprehensive validation and expanded command filtering in the web history API.
- Strengthened input validation and directory handling in the VPN configuration upload interface.
- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Important: After installing this firmware, we strongly recommend performing a factory-default reset to activate every new security adjustment.
Security Enhancements
- Password Policy Upgrade – Minimum 10 characters with at least 1 letter, 1 digit and 1 special symbol, and no consecutive identical characters; hardens defence against brute-force attacks.
- HTTPS on 8443 – Management interface now served over TLS by default.
- UPnP Disabled – Universal Plug and Play starts in the off state for reduced surface exposure.
- AiCloud Authentication Hardening (CWE-287) – Added layered verification.
- Authentication Logic Refactor – Removed redundant code paths for a lean sign-in flow.
- Memory Safety Guard (CWE-476) – Introduced null-reference protections across critical services.
- Enhanced IPsec Parameter Validation – The existing input checks have been hardened.
- Data Exposure Mitigation (CWE-200) – Reinforced controls on sensitive pathways.
- Detailed Audit Trails – Expanded logging within the authentication module.
System Improvements
- Connection Stability – Core algorithms refined for steadier links.
- Scheduling Accuracy – Timed tasks execute reliably under PPPoE, PPTP and L2TP WAN modes.
- Client List Maintenance – Resolved an issue that prevented offline devices from being removed from the client list
- Optimized various IPTV functionalities to enhance user experience and performance.
Initial firmware release