Upgrade Warranty: Here.
* Please note that the availability of the Premium Care product lines might differ by country.
- Driver & Tools
- FAQ
- Manual & Document
- Warranty
- More Service
BIOS & FIRMWARE
- Driver & Tools
- BIOS & FIRMWARE
- Enhanced system stability.
- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.
- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.
- Implemented comprehensive validation and expanded command filtering in the web history API.
- Strengthened input validation and directory handling in the VPN configuration upload interface.
- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Improved compatibility with certain IoT devices.
1.Enhanced input parameter handling techniques to improve data processing stability and system security.
2.Enhance system access control mechanisms.
1.Fixed the UI issue in Chrome.
2.Fixed client binding issues in Mesh scenarios.
Please unzip the firmware file, and then verify the checksum.
SHA256: 18ecb24ce88b32230949b711cc169993ca70b9d1e6c00ae87d4d59a0f1b28069
1. Strengthened input validation and data processing workflows to further protect information security.
2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.
3. Enhanced device security through improved buffer handling in connection features.
4. Refined data handling processes, ensuring secure and accurate information management.
5. Enhanced file access control mechanisms, promoting a more secure operating environment.
6. Strengthened certificate protection, providing enhanced data security.
1.Optimized memory management mechanisms, improving system efficiency and stability.
2.Strengthened input validation and data processing workflows, further protecting your information security.
3.Improved web rendering engine, enhancing browsing experience and security.
4.Enhanced security of system command processing to guard against potential malicious operations.
5.Perfected JavaScript-related security mechanisms, offering a more secure web interaction environment.
Please unzip the firmware file, and then verify the checksum
SHA: 2f664213e3d006825118f5f7dcac5399bc40e85e13f3afd0ad67980f27574308
- Resolved guest network connectivity issues on AiMesh nodes by disabling guest network internal access.
Please unzip the firmware file, and then verify the checksum.
SHA256: 7372a72acb04401ffd89117469b258558dcb799dad48d211ec72724e2a8dc639
Bug Fixes and Enhancements:
- Fixed v6plus related Issues.
- Fixed ipv6 network service filter not work.
- Resolved an issue that caused hostname errors in the DDNS service.
- Resolved OpenVPN Server TAP mode issue.
- Fixed the problem that the AiCloud app cannot add router on Android 9.
- Ensured consistent display of client status on the WireGuard server.
- Enhanced system stability when accessing the WireGuard Server with DMZ enabled.
- Improved stability when enabling or disabling the WireGuard server.
- Optimized memory utilization and fixed an occasional server error when registering DDNS with an app.
- Corrected a bug encountered when adding a rule to the network services filter.
Security Fixes:
- Fixed several curl vulnerabilities.
- Fixed FFmpeg vulnerabilities.
- Corrected an OpenVPN vulnerability categorized as CWE-134.
- Strengthened protection against SSH brute force attacks.
- Fixed OpenSSL vulnerabilities.
Please unzip the firmware file, and then verify the checksum.
SHA256: fec6ea6bf7b32dad25ceda9cbdbb187b6d29bbfeaeb23768184ef63a6d379ad0
New features:
-Built-in Surfshark in VPN Fusion allows you to surf the internet anonymously and securely from anywhere by encrypting connections. Please refer to https://asus.click/SurfsharkVPN
-iPhone/Android USB auto backup WAN allows you to connect your phone to the router’s USB port and use it as an internet source. Please refer to https://asus.click/AutobackupWAN
-DDNS transfer allows you to transfer your ASUS DDNS hostname from your original router to the new one. Please refer to https://asus.click/ASUSDDNS
Bug fixes and functionality modifications:
-Resolved the issue with login and password changes.
-Resolved the IPSec VPN connection issues.
-Resolved the Instant Guard connection issues.
-Fixed the AiCloud login issue after unplugging and plugging the HDD into the USB port.
-Fixed the issue where Traffic Analyzer sometimes couldn't record data.
-Fixed the time display issue for the preferred upgrade time in the Auto Firmware Upgrade function.
-Fine-tuned the description for port status.
-Enabled DynDNS and No-IP DDNS to use IPv6.
-Fixed AiMesh preferred AP identification in site survey results.
-Updated timezone list for Greenland, Mexico, and Iran.
-Modified the USB application option text in dual WAN.
-Allowed WireGuard Server clients to access the Samba server.
-Fixed memory leak issue.
-Enabled the failback function when using the iOS/Android USB backup WAN.
-The ARP response issue has been resolved, along with the connection issue between the router and the ROG Phone 6 and 7.
-Resolved the issue where the USB path is not displayed on the Media Server page in the AiMesh node
Security updates:
-Enabled and supported ECDSA certificates for Let's Encrypt.
-Enhanced protection for credentials.
-Enhanced protection for OTA firmware updates.
-Fixed DoS vulnerabilities in firewall configuration pages. Thanks to Jinghe Gao's contribution.
-Fixed DoS vulerabilities in httpd. Thanks to Howard McGreehan.
-Fixed information disclosure vulnerability. Thanks to Junxu (Hillstone Network Security Research Institute) contribution.
-Fixed CVE-2023-28702 and CVE-2023-28703. Thanks to Xingyu Xu(@tmotfl) contribution.
-Fixed null pointer dereference vulnerabilities. Thanks to Chengfeng Ye, Prism Research Group - cse hkust contribution.
-Fixed the cfg server vulnerability. Thanks to Swing and Wang Duo from Chaitin Security Research Lab.
-Fixed the vulnerability in the logmessage function. Thanks to Swing and Wang Duo from Chaitin Security Research Lab C0ss4ck from Bytedance Wuheng Lab, Feixincheng from X1cT34m.
Please unzip the firmware file, and then verify the checksum.
SHA256: 50a894191b38b7f58afd9d65e414951e47370a8018ec212c6e731a2b01a06b35
1.Fixed CVE-2022-46871
2.Fixed Client DOM Stored XSS.
3.Improved AiMesh backhaul stability.
4.Fixed AiMesh topology UI bugs.
5.Fixed the reboot issue when assigning specific clients in VPN fusion.
6.Fixed the VPN fusion bug when importing the Surfshark WireGuard conf file.
7.Fixed network map bugs.
Please unzip the firmware file first then check the MD5 code.
MD5: 65d760c3b08af461998fe0b5c870e424
If you want to upload the firmware file manually, please check your RT-AX82U firmware version is greater or equal to 3.0.0.4.386.50289. If not, please manual upgrade your RT-AX82U to 3.0.0.4.386.50289 first.
Instead of manual upgrade the firmware, we suggest you to upgrade the firmware through live update function by clicking the check firmware version in the ASUS router app--> Settings --> firmware upgrade.
Or click the check button in web GUI --> Administration --> Firmware upgrade.
Release notes:
Try more on ASUSWRT 2022 with new features at https://asus.click/ASUSWRT2022
1. Supported WireGuard VPN server and client.
2. Supported VPN fusion. It can easily achieve VPN connection to network devices like Smart TV, Game consoles and without installing the VPN client software.
3. Supported new devices connection notification.
4. Supported connection diagnostic on the ASUS router app.
5. Supported Instant Guard 2.0 which helps easily invite family or friends to join the VPN connection.
6. Upgraded parental control and added reward, new scheduler for flexible setting
7. Fixed USB icon issue in port status.
8. Fixed HTTP response splitting vulnerability. Thanks to Efstratios Chatzoglou, University of the Aegean.
9. Fixed status page HTML vulnerability. Thanks to David Ward.
10. Fixed CVE-2018-1160. Thanks to Steven Sroba.
11. Fixed cfg_server security issue.
Please unzip the firmware file first then check the MD5 code.
MD5: 862d8ddace51e4c2ff48ce4feb3ea598
The version is a middle firmware for upgrading from 3.0.0.4.386.49674 (or a lower version) to 3.0.0.4.388.2xxxx
We suggested updating the firmware by clicking the check firmware in the ASUS router app or web GUI, and you don't need to update the firmware to this version manually.
Please unzip the firmware file first then check the MD5 code.
MD5: 5c4a459a40d17b02ff31421298db0d5a
Improved connection stability.
Please unzip the firmware file first then check the MD5 code.
MD5: a362b7fbb85503a9cc611dd50832a40b
1. Improved system stability
2. Supported Safe Browsing in the router app to filter explicit content from search results. You can set it in the router app --> Devices or Family.
3. Fixed anomalous 802.11 frame issues.
Thanks to Kari Hulkko and Tuomo Untinen from The Synopsys Cybersecurity Research Center (CyRC).
Issue was found by using Defensics Fuzz Testing Tool.
4. Fixed CVE-2022-26376
Please unzip the firmware file first then check the MD5 code.
MD5: f7e07598e0da86cac73dce8ee54aea1d
1. Fixed OpenSSL CVE-2022-0778
2. Fixed CVE-2021-34174, CVE-2022-0778
3. Added more security measures to block malware.
4. Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.
5. Fixed CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-26673, CVE-2022-26674
6. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.
Please unzip the firmware file first then check the MD5 code.
MD5: f04897a4f50a4eccd6360ece01c6ca14
Security
- Fixed string format stacks vulnerability
- Fixed cross-site-scripting vulnerability
- Fixed informational vulnerability.
Thanks to Howard McGreehan.
-Fixed SQL injection vulnerability
-Fixed json file traversal vulnerability
-Fixed plc/port file traversal vulnerability
-Fixed stack overflow vulnerability
Thanks to HP of Cyber Kunlun Lab
-Fixed authenticated stored XSS vulnerability
Thanks to Luke Walker – SmartDCC
-Fixed LPD denial of service vulnerability
-Fixed cfgserver heap overflow vulnerability
-Fixed cfgserver denial of service vulnerability
Thanks to TianHe from BeFun Cyber Security Lab.
Added more ISP profile
Digi 1 - TM
Digi 2 - TIME
Digi 3 - Digi
Digi 4 - CTS
Digi 5 - ALLO
Digi 6 - SACOFA
Maxis - CTS
Maxis - SACOFA
Maxis - TNB/ALLO
Fixed AiMesh guest network issues.
Fixed DDNS issues where the WAN IP is IPv6
Fixed UI bugs in Administration --> feedback.
Fixed time zone error.
Improved the connection stability.
Please unzip the firmware file first then check the MD5 code.
MD5:d2deab6adbbb2c89545dffb662eae3ee