ASUS ZenWiFi AX Mini (XD4)
BIOS & FIRMWARE
- Driver & Tools
- BIOS & FIRMWARE
Security Fixes
-Resolved command injection vulnerability.
-Resolved DoS vulnerabilities in HTTPD and firewall configuration pages.
-Addressed ARP poisoning vulnerability.
-Addressed information disclosure vulnerability.
-Corrected code execution issue in custom OVPN.
-Corrected an OpenVPN vulnerability categorized as CWE-134.
-Corrected null pointer dereference vulnerabilities.
-Patched OpenSSL vulnerabilities.
-Fix CVE-2022-46871 and CVE-2023-35720.
-Fix CVE-2023-28702 and CVE-2023-28703.
-Fix XSS and self-reflected HTML injection vulnerabilities.
-Enabled and supported ECDSA certificates for Let's Encrypt.
-Enhanced system stability.
-Enhanced FFmpeg vulnerabilities.
-Enhanced protection for OTA firmware updates and credentials.
-Improved several curl vulnerabilities.
-Improved the cfg server vulnerability.
-Improved WireGuard performance.
-Strengthened defenses against SSH brute force attacks.
Please unzip the firmware file, and then verify the checksum.
SHA256: a604d27590eb9012a643593ce3b4f100e9e828af8c010a41fc05b24cea9b59c3
Security
- Fixed string format stacks vulnerability
- Fixed cross-site-scripting vulnerability
- Fixed informational vulnerability. Thanks to Howard McGreehan.
- Fixed SQL injection vulnerability
- Fixed json file traversal vulnerability
- Fixed plc/port file traversal vulnerability
- Fixed stack overflow vulnerability. Thanks to HP of Cyber Kunlun Lab
- Fixed authenticated stored XSS vulnerability. Thanks to Luke Walker – SmartDCC
- Fixed cfgserver heap overflow vulnerability
- Fixed cfgserver denial of service vulnerability. Thanks to TianHe from BeFun Cyber Security Lab.
- Fixed OpenSSL CVE-2022-0778
- Fixed CVE-2021-34174
- Added more security measures to block malware.
- Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.
- Fixed CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-26376
Bug fixes
- Fixed AiMesh guest network issues.
- Fixed DDNS issues where the WAN IP is IPv6
- Fixed UI bugs in Administration --> feedback.
- Fixed time zone error.
New features
- Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.
- Supported Safe Browsing in the router app to filter explicit content from search results. You can set it in the router app --> Devices or Family.
Please unzip the firmware file first then check the MD5 code.
MD5: e2ffcc895b651e2dda18f5f68f364dca
1. Fixed OpenSSL CVE-2022-0778
2. Fixed CVE-2021-34174, CVE-2022-0778
3. Added more security measures to block malware.
4. Fixed Stored XSS vulnerability. Thanks to Milan Kyselica of IstroSec.
5. Fixed CVE-2022-23970, CVE-2022-23971, CVE-2022-23972, CVE-2022-23973, CVE-2022-25595, CVE-2022-25596, CVE-2022-25597, CVE-2022-26673, CVE-2022-26674, CVE-2022-26376
6. Added 3rd party DNS server list in WAN --> DNS to help users enhance the connection security.
Please unzip the firmware file first then check the MD5 code.
MD5: 1a443c1b659f5d04d501e2e1d133a1fe
Security
- Fixed string format stacks vulnerability
- Fixed cross-site-scripting vulnerability
- Fixed informational vulnerability.
Thanks to Howard McGreehan.
-Fixed SQL injection vulnerability
-Fixed json file traversal vulnerability
-Fixed plc/port file traversal vulnerability
-Fixed stack overflow vulnerability
Thanks to HP of Cyber Kunlun Lab
-Fixed authenticated stored XSS vulnerability
Thanks to Luke Walker – SmartDCC
-Fixed LPD denial of service vulnerability
-Fixed cfgserver heap overflow vulnerability
-Fixed cfgserver denial of service vulnerability
Thanks to TianHe from BeFun Cyber Security Lab.
Added more ISP profile
Digi 1 - TM
Digi 2 - TIME
Digi 3 - Digi
Digi 4 - CTS
Digi 5 - ALLO
Digi 6 - SACOFA
Maxis - CTS
Maxis - SACOFA
Maxis - TNB/ALLO
Fixed AiMesh guest network issues.
Fixed DDNS issues where the WAN IP is IPv6
Fixed UI bugs in Administration --> feedback.
Fixed time zone error.
Improved the connection stability.
Please unzip the firmware file first then check the MD5 code.
MD5:bd3e2256103f6f4c160eafba8d295fc1
1.Fixed Let's encrypt bugs
2.Fixed httpd vulnerability
3.Fixed stack overflow vulnerability
4.Fixed DoS vunerability
Thanks for the contribution of Fans0n、le3d1ng、Mwen、daliy yang from 360 Future Security Labs
Please unzip the firmware file first then check the MD5 code.
MD5:4154de347c3a63f32f9f8abc5a5eb8e6
- Fixed the fragattacks vulnerability.
- Improve system stability.
Please unzip the firmware file first then check the MD5 code.
MD5: e4f28ec3f21c9310085ac7f89f7e2072
Security Fixed:
Fixed CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25687, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686
Please be noted this is a quick fix beta version for DNSmasq vulnerabilities. Refer to "Method 2: Update Manually" in https://www.asus.com/support/FAQ/1008000 to update this firmware.
Please unzip the firmware file first then check the MD5 code.
MD5: 7a423beaea4559490d1d7d51500f40de
1. AiMesh 2.0
- System optimization: one click in AiMesh to optimize the topology
- System Ethernet backhaul mode, all nodes will only connect by ethernet, all bands will be released for wireless clients.
- System factory default and reboot.
- Client device reconnect, make the device to offline and online again.
- Client device binding to specific AP.
- Guest WiFi on all Mesh nodes (all node need to upgrade to 3.0.0.4.386 firmware)
- Access nodes USB application.
Connection priority and Ethernet backhaul mode introduction
https://www.asus.com/support/FAQ/1044184
How to setup ASUS AiMesh or ZenWiFi Mesh Ethernet backhaul under different conditions
https://www.asus.com/support/FAQ/1044151/
2. New Family interface in ASUS router App.
ASUS Router App for iOS must greater or equal to iOS v1.0.0.5.75
Android version greater or equal to v1.0.0.5.74
3. The unit of the WiFi time scheduler goes to 1 minute.
4. Support IPSec IKE v1 and IKE v2, and you can use the Windows 10 native VPN client program to connect to the router's IPSec VPN server. The Windows 10 new FAQ is in https://www.asus.com/support/FAQ/1033576
5. 2.4 and 5G on the network map could be configured in the same tab.
6. Captcha for login can be disabled in administration -> system.
7. Printer server port can be disabled on the USB app page.
8. Clients which connect to the guest network can be viewed in the network map -->view list --> interface
9. Fix Lets encrypt not working properly.
10. Add IPTV supports for specific region.
11. Improve stability under AiMesh mode.
Please unzip the firmware file first then check the MD5 code.
MD5: 1604b95fa5519aa2ab94e959b1cb6922
- Fix mesh connection issue by enabling guest network.
- Improved system stability.
Please unzip the firmware file first then check the MD5 code.
MD5: 56e8d1d8617bfbfb573b585f7c5398ac
- Improve AiMesh stability.
- Improve wifi device connection stablility.
Please unzip the firmware file first then check the MD5 code.
MD5: 39d4ef73b09c432b20d722a54a89e168
- Initial release
Please unzip the firmware file first and then check the MD5 code.
MD5: 987379478281beac712e27abf7c8fe46