Upgrade Warranty: Here.
* Please note that the availability of the Premium Care product lines might differ by country.
- Driver & Tools
- FAQ
- Manual & Document
- Warranty
- More Service
BIOS & FIRMWARE
- Driver & Tools
- BIOS & FIRMWARE
This model was end of its life, and its firmware, utility, website, and manual will no longer be updated. For more details, please refer to https://www.asus.com/event/network/eol-product/
Security Fixes
- Enhanced DNS name handling to address a potential memory issue that could occur in rare cases during name format conversion, improving system security and robustness.
- Improved safeguards for execution modules to reduce the risk of substitution during certain processes.
This model was end of its life, and its firmware, utility, website, and manual will no longer be updated. For more details, please refer to https://www.asus.com/event/network/eol-product/
-Enhanced system stability.
-Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.
-Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
- Fixed CVE-2024-3079 and CVE-2024-3080. Thanks to the contribution of swing from Chaitin Security Research Lab.
- Fixed command injection vulnerability.
- Fixed the ARP poisoning vulnerability. Thanks to the contribution of Xin'an Zhou.
- Fixed code execution in custom OVPN. Thanks to the contrubution of Jacob Baines.
- Fixed the injection vulnerability in AiCloud.
- Fixed stack buffer overflow in lighttpd. Special thanks to Viktor Edstrom.
- Fixed CVE-2023-35720
- Fixed the code execution vulnerability in AiCloud. Thanks to the contribution of chumen77.
- Fixed the XSS and Self-reflected HTML injection vulnerability. Thanks to the contrubution of Redfox Cyber Security.
*Please be advised that due to a security upgrade in AiMesh, we strongly recommend against downgrading to previous firmware versions, as this may lead to connection issues. Should you encounter any difficulties, resetting the AiMesh router to its default settings and re-establishing the mesh connection can resolve the problem.
Please unzip the firmware file, and then verify the checksum.
SHA256: aded7987b384440cffc24755a9e5005d09174bf4d2836ba8e50c3bca8866b755
1. Resolved an issue causing excessive log generation due to bwdpi issue.
2. Fixed a potential issue causing higher CPU utilization.
Please unzip the firmware file, and then verify the checksum.
SHA256: 3cab24791b71b4cdd2d2580a7f549da9b77ca5287a713b893776f0ff087f07ae
Security updates:
-Enhanced protection for credentials.
-Fixed DoS vulnerabilities in firewall configuration pages. Thanks to Jinghe Gao's contribution.
-Fixed DoS vulerabilities in httpd. Thanks to Howard McGreehan.
-Fixed information disclosure vulnerability. Thanks to Junxu (Hillstone Network Security Research Institute) contribution.
-Fixed CVE-2023-28702 and CVE-2023-28703. Thanks to Xingyu Xu(@tmotfl) contribution.
-Fixed null pointer dereference vulnerabilities. Thanks to Chengfeng Ye, Prism Research Group - cse hkust contribution.
-Fixed the cfg server vulnerability. Thanks to Swing and Wang Duo from Chaitin Security Research Lab.
-Fixed the vulnerability in the logmessage function CVE-2023-35086/ CVE-2023-35087. Thanks to Swing and Wang Duo from Chaitin Security Research Lab C0ss4ck from Bytedance Wuheng Lab, Feixincheng from X1cT34m.
Please unzip the firmware file, and then verify the checksum.
SHA256: fa1f20a717950885bb7eaef40910a6b827c3d68418b1ca143ccc3555d782e3cc
1.Fixed HTTP response splitting vulnerability.
2.Fixed cfg server security issues.
3.Fixed Open redirect vulnerability.
4.Fixed token authentication security issues.
5.Fixed security issues on the status page.
6.Fixed XSS vulnerability.
7.Fixed CVE-2022-26376
8.Fixed CVE-2018-1160
9.Optimize the AiMesh web interface
10.Improved AiMesh connection stability.
Please unzip the firmware file first then check the MD5 code.
MD5: bc9aa1423070d398c409186e5aae1e69
1. Fixed CVE-2018-1160, CVE-2022-26376, CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2021-41435, CVE-2021-41436, CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-CVE-2022-25595, CVE-2022-25596, CVE-2022-25596
2. Fixed httpd vulnerability
3. Fixed stack overflow vulnerability
4. Fixed DoS vulnerability
5. Fixed Stored XSS vulnerability.
6. Fixed string format stacks vulnerability
7. Fixed cross-site-scripting vulnerability
8. Fixed informational vulnerability.
9. Fixed SQL injection vulnerability
10. Fixed json file traversal vulnerability
12. Fixed stack overflow vulnerability
13. Fixed cfgserver heap overflow vulnerability
14. Fixed cfgserver denial of service vulnerability
Please unzip the firmware file first then check the MD5 code.
MD5: f64b96bacf2dae563152d684d835f68b
1. Fixed Let’s Encrypt not working properly.
2. Added IPTV supports for specific region.
3. Fixed parental control issues.
This firmware add more security protection for configuration.
4. Fixed pre-auth RCE chain through arbitrary file write, special thanks for Robert Chen's contribution
If you want to manually downgrade to previously version, please reset the router to default after downgraded.
Please unzip the firmware file first then check the MD5 code.
MD5: 97e1195fa52299f874f44fb337ed60c7
Security update
- Fixed CVE-2020-12695 (CallStranger)
- Fixed Reflected XSS vulnerability.
- Fixed Directory traversal vulnerability.
- Fixed CVE-2017-15653.
The update server transport layer security was upgraded and the old protocol was removed.
Please refer to the "Update Manually" section in https://www.asus.com/support/FAQ/1008000 to update the firmware.
Please unzip the firmware file first then check the MD5 code.
MD5: 011ea1c128d797ec7968f4b3fa94a1df
- Fixed firmware update issues.
Please unzip the firmware file first then check the MD5 code.
MD5: 08d9267b41e4591beff49e4a78c15670
- Improved AiMesh stability
Please unzip the firmware file first then check the MD5 code.
MD5: d4b05802468b71f7510c3daeaa7fed4d
Initial release
Please unzip the firmware file first then check the MD5 code.
MD5: b4fea025e37f76157c32541a2ea4b19c
