• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

ASUS Issues Router Product Security Advisory

Joined
Feb 21, 2006
Messages
1,986 (0.30/day)
Location
Toronto, Ontario
System Name The Expanse
Processor AMD Ryzen 7 5800X3D
Motherboard Asus Prime X570-Pro BIOS 5013 AM4 AGESA V2 PI 1.2.0.Ca.
Cooling Corsair H150i Pro
Memory 32GB GSkill Trident RGB DDR4-3200 14-14-14-34-1T (B-Die)
Video Card(s) AMD Radeon RX 7900 XTX 24GB (24.3.1)
Storage WD SN850X 2TB / Corsair MP600 1TB / Samsung 860Evo 1TB x2 Raid 0 / Asus NAS AS1004T V2 14TB
Display(s) LG 34GP83A-B 34 Inch 21: 9 UltraGear Curved QHD (3440 x 1440) 1ms Nano IPS 160Hz
Case Fractal Design Meshify S2
Audio Device(s) Creative X-Fi + Logitech Z-5500 + HS80 Wireless
Power Supply Corsair AX850 Titanium
Mouse Corsair Dark Core RGB SE
Keyboard Corsair K100
Software Windows 10 Pro x64 22H2
Benchmark Scores 3800X https://valid.x86.fr/1zr4a5 5800X https://valid.x86.fr/2dey9c
That's the version I've been using and experiencing the issue with.
What troubleshooting have you done so for?

Factory reset?
Forgetting the wifi on all affected device and rejoining?

Does stock firmware also show the same thing?
 
Joined
Aug 23, 2013
Messages
454 (0.12/day)
I'm safe as I use it only as an access point. I have a different main router.
 
Joined
Sep 5, 2004
Messages
1,956 (0.27/day)
Location
The Kingdom of Norway
Processor Ryzen 5900X
Motherboard Gigabyte B550I AORUS PRO AX 1.1
Cooling Noctua NB-U12A
Memory 2x 32GB Fury DDR4 3200mhz
Video Card(s) PowerColor Radeon 5700 XT Red Dragon
Storage Kingston FURY Renegade 2TB PCIe 4.0
Display(s) 2x Dell U2412M
Case Phanteks P400A
Audio Device(s) Hifimediy Sabre 9018 USB DAC
Power Supply Corsair AX850 (from 2012)
Software Windows 10?
"However, if you're running the third party Asuswrt-Merlin firmware, you're apparently safe, as the author of the third party firmware has already patched all the known security issues that ASUS has announced patches for."

third party does asus own work, i used to havea asus router and merlin firmware was pretty good, its similar to stock but has alot of good fixes and other updates
 
Joined
May 13, 2008
Messages
669 (0.11/day)
System Name HTPC whhaaaat?
Processor 2600k @ 4500mhz
Motherboard Asus Maximus IV gene-z gen3
Cooling Noctua NH-C14
Memory Gskill Ripjaw 2x4gb
Video Card(s) EVGA 1080 FTW @ 2037/11016
Storage 2x512GB MX100/1x Agility 3 128gb ssds, Seagate 3TB HDD
Display(s) Vizio P 65'' 4k tv
Case Lian Li pc-c50b
Audio Device(s) Denon 3311
Power Supply Corsair 620HX
"However, if you're running the third party Asuswrt-Merlin firmware, you're apparently safe, as the author of the third party firmware has already patched all the known security issues that ASUS has announced patches for."

third party does asus own work, i used to havea asus router and merlin firmware was pretty good, its similar to stock but has alot of good fixes and other updates

Yeah, Merlin is for-sure a major hero wrt (no pun intended) this scene. IMO, it is the number one reason to buy any consumer router. The fact they often work on/constantly update software (beyond Asus) leveraging what is often the best (performance/feature-wise) platform is somewhere between a convenient coincidence and necessity. He is the flip-side to the coin that is the Asus hardware team, unlike the software team (as we've seen in many instances: from mobos, to routers, to the Ally, fumble the ball or do heavy-handed/non-optimized stuff leading to problems). Asus has always appeared to me to be a company that does things through brute force and kitchen-sink approach rather than tactically (something I use to also associate with MSI), and he is the missing piece that completes the package in this particular category.

Think of him similar to a guy that would've preemptively made a home-brew bios to optimize chipset voltage/LLC to optimally/efficiently make use of their high-end motherboard hardware, rather than just cranking it up to 'win' and potentially blowing it up. Asus is a sledgehammer and this guy is a scalpel. More aptly, Asus makes a sports car pushed to it's stock limit with a bloated feature-set of software. Merlin is the nimble tuner/optimizer/plug-in version update guy which will make that car better/more reliable, but also will also back-port the software performance/optimization/features to your older soccer-mom car with the same or similarly-applicable engine. Or something like that. I don't know: I'm a nerd, not a car guy. You get what I mean, hopefully. Good hardware needs not just good, but well-managed software. Asus is robust in every way, but inefficient. He makes the best better, and doesn't make the mistakes/choices (for market/planned-obsolescence/support cost reasons) the actual OEM does.

I don't know how closely you or anyone else follows it, but I seem to recall him doing all kinds of work to manage plug-in/feature updates within the main memory and nvram/eeprom, and has even expounded upon potential problems/inefficiencies he's fixed in the past (some of which did not become a big public deal for 'stock' users). My understanding is where-as most stock/open firmware keeps old configurations/settings (it's essentially additive), he routinely goes through the whole damn thing to keep everything tidy; add features (to old/other hardware) where possible and up-to-date (beyond what Asus does/can do in a timely manner) while avoiding potential buffer overflow problems at all cost.

I didn't realize how much of an issue these things potentially could be until I heard of others using stock/other firmware having reliability issues they didn't understand; it turns out running out of nvram post-updates. There was also Asus own recent very-public back-end blunder wrt how their routers handle security re: memory management that took down damn near everything. It proved not only what he was doing is 'optimal', but correct, and needed, optimization, for everything to run to best potential/capability/reliability.

The most he asks for is a manual restart or the very-occasional factory reset to keep things smooth, and explains why very well in both forum posts and included read-mes. Very cool/knowledgeable/professional cat. His 3-minute update percentage bar also only takes about 2 minutes of operation in reality (essentially it will be done before you think it should be), which sums it all up pretty well. Guy tapping temple gif.

He also supports routers as long as humanly possible (essentially they have too little memory for him to add/update Asus' bloated features or they cut an applicable driver branch). While you could argue (some of the) work should be done by Asus, and it should, I honestly question if they are similarly capable, and obviously they purposely wouldn't do some things he implements for people.

The value of what he (constantly/consistently) does is kind of immeasurable, and is the exactly correct person for the job doing it the only way it can realistically be done.
 
  • Like
Reactions: Jun

Jun

Joined
May 6, 2022
Messages
47 (0.06/day)
System Name Alpha
Processor AMD Ryzen 7 5800X3D [PBO2 tuner -30 all cores]
Motherboard GIGABYTE B550I AORUS PRO AX (rev. 1.0)
Cooling ekwb EK-AIO 240 D-RGB
Memory Trident Z Neo DDR4-3600 CL16 32GB GTZN [15-15-15-35 3800MHz@1.45V]
Video Card(s) INNO3D GEFORCE RTX 3080 TI X3 OC [2010MHz@993mV]
Storage Kingston FURY Renegade 2TB
Display(s) Samsung Odyssey G7 32” // ASUS ROG Strix XG16AHP
Case Lian Li A4-H2O
Audio Device(s) CREATIVE Sound BlasterX G6 // polk MagniFi Mini //SHURE SE846 //steelseries Arctis Nova Pro Wireless
Power Supply SilverStone SX750 Platinum V1.1
Mouse Logitech G303 SHROUD EDITION
Keyboard Logitech G915 TKL Linear
Software Microsoft Windows 11 Pro
Merlin firmware is the only reason I would consider ASUS router. I had great experience with it over stock.
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
Combine the ongoing router dramas with the UEFI rootkits going to hardcoded HTTP addresses on gigabyte boards, and you could make a botnet that can spread pretty scarily
 
Top