Upgrade Warranty: Here.
* Please note that the availability of the Premium Care product lines might differ by country.
- Driver & Tools
- FAQ
- Manual & Document
- Warranty
- More Service
BIOS & FIRMWARE
- Driver & Tools
- BIOS & FIRMWARE
This update includes a required change for the Speedtest service. If Speedtest is supported on your model, you must install this update to continue using it. Please refer to Speedtest Service Announcement for details.
https://www.asus.com/support/faq/1057454/
Supports Surfshark VPN account login for a smoother user experience. (Supported model only)
Security Fixes
Web management interface: Strengthened data handling for the connected device list and added stricter content checks when importing configuration profiles.
Network speed test service: Added allowlist validation for service command parameters, so that only expected values are accepted.
AiCloud: Strengthened the data handling mechanism for the network neighborhood host list.
AiCloud: Improved how share link identifiers are generated, and adjusted the file and disk information query process.
AiCloud: Strengthened authentication and path validation for remote file access.
System protection service: Adjusted address parameter validation and event logging, strengthening access control between local services.
Certificate import process: Adjusted file handling and password passing, with stricter parameter validation.
Third-party account authorization: Narrowed the recipients of authorization data to better protect authorization information.
Web management interface: Adjusted the output handling of feedback content.
Notification service: Added identity verification for local connection sources and tightened the related file permission settings.
Mobile device connection authorization: Added a device matching check to strengthen the access token issuance process.
Device discovery service: Removed a non-essential internal function endpoint to strengthen overall access control.
AiMesh: Adjusted data access protection during the node joining process, improving system stability while connections are being established.
System temporary directory: Adjusted the default permissions applied at creation time to narrow local file access.
Network diagnostic data query: Strengthened value range checks for time interval parameters.
Network diagnostic data query: Added allowlist validation for query fields.
Internal data query: Improved field matching logic and optimized the memory release process under error conditions.
Time synchronization settings: Strengthened parameter validation for the server name.
File upload handling: Fixed an issue where certain input formats could cause the web management service to become unresponsive.
Wireless channel selection tool: Adjusted the handling of command parameters to prevent unintended command execution.
Certificate upload: Added a pre-check of archive contents to prevent files from being written to unintended locations.
System configuration file generation: Strengthened parameter content checks to prevent abnormal configuration values from affecting network service settings.
VPN and account authentication services: Adjusted the handling of connection settings and account data, with stricter parameter validation.
We recommend updating to this version to maintain optimal protection.
New Features
- New Time Zone Options: Added "Vancouver, Whitehorse (PST7)" and "Edmonton, Yellowknife (MST6)" time zone options for Canada.
Bug Fixes and Enhancements
- Improved stability during the AiMesh node setup process.
- Strengthened firewall rule configuration for UPnP, improving port-forwarding stability and firewall rule restoration reliability.
Security Fixes
- Strengthened data handling in Networks configuration functions.
- Improved data validation in Networks rule list processing.
- Fixed a data-handling issue in the DNS query caching component.
- Strengthened verification when a software component downloads external resources, improving connection security.
- Adjusted the information response mechanism of the device discovery service, strengthening protection of device information.
- Fixed a data-handling issue in a firmware component on a specific model.
- Strengthened input data validation in a device-pairing web function.
- Improved data validation in the configuration file upload/sync function.
- Improved how the account service restart process is handled.
- Removed a non-essential internal function endpoint, strengthening overall access control.
- Adjusted the debug file access mechanism, strengthening protection of internal data.
- Strengthened data handling in the system logging function.
We recommend upgrading to this version to maintain optimal protection.
Security:
-Strengthened input sanitization mechanism.
- Enhanced system stability.
- Enhanced input validation and refactored legacy string handling routines to ensure robust memory management.
- Mitigated security risks in AiCloud service by enforcing strict credential verification, implementing robust file path validation, and hardening command execution logic to prevent unauthorized access and manipulation of system resources.
- Implemented comprehensive validation and expanded command filtering in the web history API.
- Strengthened input validation and directory handling in the VPN configuration upload interface.
- Fixed an issue that allowed certain user settings to be bypassed, improving overall user control and protection.
Important: After installing this firmware, we strongly recommend performing a factory-default reset to activate every new security adjustment.
Security Enhancements
- Password Policy Upgrade – Minimum 10 characters with at least 1 letter, 1 digit and 1 special symbol, and no consecutive identical characters; hardens defense against brute-force attacks.
- HTTPS on 8443 – Management interface now served over TLS by default.
- UPnP Disabled – Universal Plug and Play starts in the off state for reduced surface exposure.
- AiCloud Authentication Hardening (CWE-287) – Added layered verification.
- Authentication Logic Refactor – Removed redundant code paths for a lean sign-in flow.
- Memory Safety Guard (CWE-476) – Introduced null-reference protections across critical services.
- Enhanced IPsec Parameter Validation – The existing input checks have been hardened
- Data Exposure Mitigation (CWE-200) – Reinforced controls on sensitive pathways.
- Detailed Audit Trails – Expanded logging within the authentication module.
System Improvements
- Connection Stability – Core algorithms refined for steadier links.
- Scheduling Accuracy – Timed tasks execute reliably under PPPoE, PPTP and L2TP WAN modes.
- Client List Maintenance – Resolved an issue that prevented offline devices from being removed from the client list.
Bug Fixes:
- Fixed abnormal client list.
- Fixed abnormal GUI behavior of Wireguard VPN.
- Fixed USB internet backup conflict with main WAN.
- Fixed abnormal WAN detection while AiDetection is enabled.
- Improved AdGuard DNS GUI issues.
- Fixed IPv6 related issues.
- Improved USB tether compatibility for pixel phones.
Improved compatibility with certain IoT devices.
1.Enhanced input parameter handling techniques to improve data processing stability and system security.
2.Enhance system access control mechanisms.
1.Fixed the UI issue in Chrome.
2.Fixed client binding issues in Mesh scenarios.
Please unzip the firmware file, and then verify the checksum.
SHA256: 263ba5196f9b5d8cf0dcdc5e79051aa338fe0d23a681bc326d30ce38bf34792f
Improved the ability to modify the HTTPS port in AP mode via the web UI.
1. Strengthened input validation and data processing workflows to further protect information security.
2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.
3. Enhanced device security through improved buffer handling in connection features.
4. Refined data handling processes, ensuring secure and accurate information management.
5. Enhanced file access control mechanisms, promoting a more secure operating environment.
6. Strengthened certificate protection, providing enhanced data security.
Please unzip the firmware file, and then verify the checksum.
SHA256: 1cc7d3206cfbd89a54a099a973d9c44a279b55144c7bd97f25d99445ade19e7d
1. Strengthened system code execution processes.
2. Enhanced AiCloud password protection mechanisms, safeguarding against unauthorized access attempts.
3. Refined input validation in the web interface, ensuring a more secure web interaction environment.
4. Improved data export functionality in the admin portal, ensuring accurate and secure handling of client information.
5. Optimized memory management mechanisms, improving system stability.
6. Improved system buffer management, ensuring reliable data processing workflows.
7. Enhanced stack buffer management, promoting greater system stability.
Please unzip the firmware file, and then verify the checksum.
SHA256: d155df280e4e64cea5efef8468a6b9eeec6038fd73f0ee73a2cea1c4ee0ec694