Upgrade Warranty: Here.
* Please note that the availability of the Premium Care product lines might differ by country.
- Driver & Tools
- FAQ
- Manual & Document
- Warranty
- More Service
BIOS & FIRMWARE
- Driver & Tools
- BIOS & FIRMWARE
This update includes a required change for the Speedtest service. If Speedtest is supported on your model, you must install this update to continue using it. Please refer to Speedtest Service Announcement for details.
https://www.asus.com/support/faq/1057454/
Supports Surfshark VPN account login for a smoother user experience. (Supported model only)
Security Fixes
Web management interface: Strengthened data handling for the connected device list and added stricter content checks when importing configuration profiles.
Network speed test service: Added allowlist validation for service command parameters, so that only expected values are accepted.
System protection service: Adjusted address parameter validation and event logging, strengthening access control between local services.
Certificate import process: Adjusted file handling and password passing, with stricter parameter validation.
Third-party account authorization: Narrowed the recipients of authorization data to better protect authorization information.
Web management interface: Adjusted the output handling of feedback content.
Notification service: Added identity verification for local connection sources and tightened the related file permission settings.
Mobile device connection authorization: Added a device matching check to strengthen the access token issuance process.
Device discovery service: Removed a non-essential internal function endpoint to strengthen overall access control.
AiMesh: Adjusted data access protection during the node joining process, improving system stability while connections are being established.
System temporary directory: Adjusted the default permissions applied at creation time to narrow local file access.
Network diagnostic data query: Strengthened value range checks for time interval parameters.
Network diagnostic data query: Added allowlist validation for query fields.
Internal data query: Improved field matching logic and optimized the memory release process under error conditions.
Time synchronization settings: Strengthened parameter validation for the server name.
File upload handling: Fixed an issue where certain input formats could cause the web management service to become unresponsive.
Wireless channel selection tool: Adjusted the handling of command parameters to prevent unintended command execution.
Certificate upload: Added a pre-check of archive contents to prevent files from being written to unintended locations.
System configuration file generation: Strengthened parameter content checks to prevent abnormal configuration values from affecting network service settings.
VPN and account authentication services: Adjusted the handling of connection settings and account data, with stricter parameter validation.
We recommend updating to this version to maintain optimal protection.
Security fixes
- Applied multiple security hardening updates across system components.
- Improved input validation and request-handling protections in selected paths.
- Included security fixes in affected services/modules (including bundled components).
- Added defenses for memory-safety and injection-related risk patterns.
Security Fixes
- Enhanced system security by addressing an unsafe remote script execution mechanism in.
- Improved system security by addressing a heap buffer overflow vulnerability during cache handling.
We recommend upgrading to this version to ensure up-to-date protection.
Improvements:
Optimized Wi-Fi roaming stability for devices supporting 802.11k but not allowing 11v.
Improved Wi-Fi roaming compatibility and stability for iOS 26 devices.
Refined accessibility-related UI and interaction details.
Improved overall remote connection stability.
Improved system behavior when using System diagnostic on feedback page.
Security Enhancements:
Strengthened input sanitization mechanism.
Enhanced system API validation for stronger protection consistency.
Strengthened command handling and system resource access controls.
Improved system logging and security event recording mechanisms.
- Enhanced system stability.
- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.
- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.
- Implemented comprehensive validation and expanded command filtering in the web history API.
- Strengthened input validation and directory handling in the VPN configuration upload interface.
- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Important: After installing this firmware, we strongly recommend performing a factory-default reset to activate every new security adjustment.
Security Enhancements
- Password Policy Upgrade – Minimum of 10 characters, including at least one letter, one digit, and one special character; disallows consecutive identical characters; hardens defense against brute-force attacks.
- HTTPS on 8443 – Management interface now served over TLS by default.
- UPnP Disabled – Universal Plug and Play starts in the off state for reduced surface exposure.
- Authentication Logic Refactor – Removed redundant code paths for a lean sign-in flow.
- Memory Safety Guard (CWE-476) – Introduced null-reference protections across critical services.
- Enhanced IPsec Parameter Validation – The existing input checks have been hardened.
- Data Exposure Mitigation (CWE-200) – Reinforced controls on sensitive pathways.
- Detailed Audit Trails – Expanded logging within the authentication module.
System Improvements
- Connection Stability – Core algorithms refined for steadier links.
- Scheduling Accuracy – Timed tasks execute reliably under PPPoE, PPTP and L2TP WAN modes.
- Client List Maintenance – Resolved an issue that prevented offline devices from being removed from the client list
1. Fixed the UI issue in Chrome.
2. Fixed client binding issues in Mesh scenarios.
3. Enhanced input parameter handling techniques to improve data processing stability and system security.
4. Enhance system access control mechanisms.
Please unzip the firmware file, and then verify the checksum.
SHA256: 2b01c1dded697ceca54e454d5edc3fa28f9f9ccaa1a1beb38cc6c0ba217fefa7
1. Strengthened input validation and data processing workflows to further protect information security.
2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.
3. Enhanced device security through improved buffer handling in connection features.
4. Refined data handling processes, ensuring secure and accurate information management.
5. Enhanced file access control mechanisms, promoting a more secure operating environment.
6. Strengthened certificate protection, providing enhanced data security.