Update your firmware immediately if you own one of these 19 Asus routers

Daniel Sims

Posts: 1,376   +43
Staff
PSA: Asus has released fixes for several security vulnerabilities affecting nearly two dozen router models. Some of the security flaws are considered critical, and even one dates back to 2018. Users can download the latest firmware by logging into their routers and running the automatic updater tool or by manually installing the firmware update from the Asus support website.

Owners of various Asus RT, GT, ZenWifi, and TUF routers should check for firmware updates as soon as possible. This week, the company released a security patch resolving nine vulnerabilities that could potentially result in denial of service or remote code execution attacks.

One of the most critical flaws addressed could cause memory corruption after an attacker sends a specifically tailored HTTP request. The update also resolves a critical vulnerability that security researchers have been tracking since 2018, which allows hackers to execute arbitrary code via an out-of-bounds write.

All of the other security issues are classified as high severity. One of these flaws facilitates man-in-the-middle attacks, enabling hackers to hijack user sessions, while another may leak sensitive information when a network request is sent by an attacker. Two vulnerabilities, which were discovered as recently as this month, could enable an unauthorized user to terminate service. Furthermore, this patch enhances credential protection and fortifies the security of over-the-air updates.

The situation impacts the following router models. Each link below leads to the corresponding manual firmware download on the Asus support site.

To perform an auto-update, connect a computer to the router, then enter the router's IP address into a web browser's address bar to access the device's web user interface. You can find the IP address using the Asus Device Discovery Utility.

Upon accessing the router's web user interface, a notification will appear in the top right corner if a firmware update is available. Click the "Firmware Upgrade" button to download and install the patch, a process that should take a few minutes.

Alternatively, you can manually update the firmware. To do so, download and unzip the appropriate firmware from the Asus support site, then click the "Upload" button found next to the phrase "Manual firmware update" near the bottom of the firmware upgrade page. Once the file window opens, select the unzipped firmware file to begin the update.

Asus recommends resetting the router to factory settings after applying the patch. The company's FAQ page contains further instructions.

Masthead credit: Dong Knows Tech

Permalink to story.

 
My router is on the list, but when I manually checked (through the router itself) to see if a new firmware was available it said my router is up to date. Last time the firmware updated was back on 5/25/2023.

I checked the firmware version on my router (3.0.0.4.388_23285) and then I went on Asus website to manually find the most recent driver. I pulled up my router by serial number on their site and went to the BIOS/Firmware page for it and it shows the most recent driver for my RT-AX82U is 3.0.0.4.388_23285 that was released on 5/25/2023.

So, that leaves us with 1 of 3 things:
1) My router isn't supposed to be on the list
2) They haven't released the updated firmware for it (and possibly other routers) yet
3) ASUS pushed out the firmware weeks ago and this story is way behind or ASUS is just way behind in releasing this information to the public.
 
I may have given in and just stupid bought one thinking it was a good upgrade.
Not sure it was.
Saw the lifetime AI security that requires all info to pass through Trend Micro.
And then the wpa3 security, you get told, don't use that, so many devices that are incompatible.
Then WTF is the point sellin me this turd?

I wanted a TP-Link as I heard better security, but then they are all exploited too.
Freaking madness.
 
On auto update and was current. AX58U works great as a wifi access point along with three Zenwifi AX Minis. I have Pfsense on a microPC as my internet router.
 
Back