What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Lot's of CVEs, (More Firmware Updates to Come, I Hope)!

jzchen

Very Senior Member
Note that many of those (newest ones) are not for routers, and they also have notes like "ASUS has released mitigations for these vulnerabilities. To protect your devices, ASUS strongly recommends that all users update their router firmware to the latest version immediately." So they have already been patched.
 
Last edited:
Note that many of those (newest ones) are not for routers, and they also have noted like "ASUS has released mitigations for these vulnerabilities. To protect your devices, ASUS strongly recommends that all users update their router firmware to the latest version immediately." So they have already been patched.
you mean that firmwares 3.0.0.4_386, 3.0.0.4_388 and 3.0.0.6_102 from November 25th, 2025 are not routers? Where do you get this... ?
 
you mean that firmwares 3.0.0.4_386, 3.0.0.4_388 and 3.0.0.6_102 from November 25th, 2025 are not routers? Where do you get this... ?
I think he was referring to the whole of that page rather than just the November 25th entries.
 
Going to the details, it clearly states "ASUS recommends update the latest firmware (released on 2025-10) to mitigate the disclosed vulnerabilities." So the listed vulnerabilities have been patched, which explains why Asus released new firmware across the product line in October 2025 — like most vendors, the detailed announcement of the specific vulnerabilities that were addressed did not come until after the patches were released for all affected routers.
 
Meanwhile in light of this latest round of security vulnerability patches, RMerlin announces he's removing AiCloud support from Asus-Merlin firmware:
[Announcement] Removal of AiCloud from Asuswrt-Merlin
Yet another major security vulnerability being discovered in AiCloud, so I'm done with it. Next Asuswrt-Merlin releases will be removing AiCloud support.

Use a VPN, or switch back to stock (and deal with the constant security risks associated with it) if you need remote file access.
 
I never useed AICloud on my router. Is it now possible for routers to get hit, even with it not in use? It seems pretty serious if RMerlin removed it completely.
 
I never useed AICloud on my router. Is it now possible for routers to get hit, even with it not in use? It seems pretty serious if RMerlin removed it completely.
No. If you don't enable AiCloud then it doesn't run. Therefore there's nothing to attack.
 
Similar threads
Thread starter Title Forum Replies Date
T More than one DDNS ASUSWRT - Official 4

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Members online

Back
Top