- ドライバーとツール
- 知識
- マニュアルとドキュメント
- 保証
- More Service
BIOS & FIRMWARE
- Driver & Tools
- BIOS & FIRMWARE
This update includes a required change for the Speedtest service. If Speedtest is supported on your model, you must install this update to continue using it. Please refer to Speedtest Service Announcement for details.
https://www.asus.com/support/faq/1057454/
Supports Surfshark VPN account login for a smoother user experience. (Supported model only)
Security Fixes
Web management interface: Strengthened data handling for the connected device list and added stricter content checks when importing configuration profiles.
Network speed test service: Added allowlist validation for service command parameters, so that only expected values are accepted.
AiCloud: Strengthened the data handling mechanism for the network neighborhood host list.
AiCloud: Improved how share link identifiers are generated, and adjusted the file and disk information query process.
AiCloud: Strengthened authentication and path validation for remote file access.
System protection service: Adjusted address parameter validation and event logging, strengthening access control between local services.
Certificate import process: Adjusted file handling and password passing, with stricter parameter validation.
Third-party account authorization: Narrowed the recipients of authorization data to better protect authorization information.
Web management interface: Adjusted the output handling of feedback content.
Notification service: Added identity verification for local connection sources and tightened the related file permission settings.
Mobile device connection authorization: Added a device matching check to strengthen the access token issuance process.
Device discovery service: Removed a non-essential internal function endpoint to strengthen overall access control.
AiMesh: Adjusted data access protection during the node joining process, improving system stability while connections are being established.
System temporary directory: Adjusted the default permissions applied at creation time to narrow local file access.
Network diagnostic data query: Strengthened value range checks for time interval parameters.
Network diagnostic data query: Added allowlist validation for query fields.
Internal data query: Improved field matching logic and optimized the memory release process under error conditions.
Time synchronization settings: Strengthened parameter validation for the server name.
File upload handling: Fixed an issue where certain input formats could cause the web management service to become unresponsive.
Wireless channel selection tool: Adjusted the handling of command parameters to prevent unintended command execution.
Certificate upload: Added a pre-check of archive contents to prevent files from being written to unintended locations.
System configuration file generation: Strengthened parameter content checks to prevent abnormal configuration values from affecting network service settings.
VPN and account authentication services: Adjusted the handling of connection settings and account data, with stricter parameter validation.
We recommend updating to this version to maintain optimal protection.
Security Fixes
- Enhanced input validation and protection to reduce the risk of command injection and SQL injection.
- Hardened environment variable handling.
- Hardened protections around specific logging/command composition flows to reduce potential injection risks.
- Patched a command injection risk in a specific network diagnostic function.
We recommend upgrading to this version to maintain best protection.
Improved AiMesh stability.
Fixed minor GUI bugs.
- Enhanced system stability.
- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.
- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.
- Implemented comprehensive validation and expanded command filtering in the web history API.
- Strengthened input validation and directory handling in the VPN configuration upload interface.
- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Bug Fixes and Enhancements:
Fixed Ipsec VPN related issues.
Improved Wireless compativity.
Add more localized internet connection types support.
Security:
Implemented a security patch to address an OpenVPN issue.
Initial firmware release