There's a new firmware, not officially released on the website, but shows up on the app and web GUI check for udpates. Haha I took the old link for RT-AX5400 and substituted RT-BE92U and the firmware number with the new firmware number:
I'm not going to install it yet because the firmware updater on the app and web GUI do not currently work for it, and hope to help them verify it works when they possibly resolve it. From the web GUI...
Firmware version 3.0.0.6_102_38961-gbc4c3f1_1425-g5f426
- Release note -
Important:
After installing this firmware, we strongly recommend performing a factory-default reset to activate every new security adjustment.
Security Enhancements:
- Password Policy Upgrade – Minimum 10 characters with at least 1 letter, 1 digit and 1 special symbol, and no consecutive identical characters; hardens defense against brute-force attacks.
- HTTPS on 8443 – Management interface now served over TLS by default.
- UPnP Disabled – Universal Plug and Play starts in the off state for reduced surface exposure.
- AiCloud Authentication Hardening (CWE-287) – Added layered verification.
- Authentication Logic Refactor – Removed redundant code paths for a lean sign-in flow.
- Memory Safety Guard (CWE-476) – Introduced null-reference protections across critical services.
- Enhanced IPsec Parameter Validation – The existing input checks have been hardened.
- Data Exposure Mitigation (CWE-200) – Reinforced controls on sensitive pathways.
- Detailed Audit Trails – Expanded logging within the authentication module.
System Improvements:
- System Stability – Reduce reboot occurrences.
- Connection Stability – Core algorithms refined for steadier links.
- Scheduling Accuracy – Timed tasks execute reliably under PPPoE, PPTP and L2TP WAN modes.
- Client List Maintenance – Resolved an issue that prevented offline devices from being removed from the client list.