@RMerlin - are you able to provide any info on what the Asus GPL 386_45
581 brings with it by way of bug and security fixes??
I have searched far and wide [within Asus support webui; this forum; Google; Bing etc] and can find no evidence that Asus firmware was ever compiled and released from this particular GPL.
I don't have a list, because it's not an official release, but the snapshot that was taken at the moment Asus were fighting to get the GPL-related licensing issues sorted out. They were not going to re-build new version for validation every 2-3 weeks, which would have delayed everything even further more.
You can do your own search on Asus's release notes from past releases to see what was fixed between 42095 and 45898. Obviously, Asus didn't fix everything in 45897 and released that as 45898, they have gone through hundreds of interim builds between the two over the span of 6 months.
Let's have a look at releases that occurred BEFORE 45581 on which I am currently working:
Code:
Version 3.0.0.4.386.45375
2021/08/31 71.45 MBytes
ASUS RT-AX88U Firmware version 3.0.0.4.386.45375
This version includes several vulnerability patches.
BusyBox
- CVE-2016-2148
- CVE-2016-6301
- CVE-2018- 1000517
cURL
- CVE-2020-8169
- CVE-2019-5481
- CVE-2019-5482
- CVE-2018-1000120
- CVE-2018- 1000300
- CVE-2018-16839
Lighttpd
- CVE-2018-19052
Linux
- CVE-2020-14305
- CVE-2020-25643
- CVE-2019-19052
lldpd
- CVE-2020-27827
Avahi
- CVE-2017-6519
hostapd
- CVE-2021-30004
- CVE-2019-16275
OpenVPN
- CVE-2020-11810
- CVE-2020-15078
wpa
- CVE-2021-30004
- CVE-2021-27803
- CVE-2019-11555
- CVE-2019-9499
- CVE-2019-9498
- CVE-2019-9497
- CVE-2019-9496
- CVE-2019-9495
- CVE-2019-9494
- CVE-2017-13086
- CVE-2017-13084
- CVE-2017-13082
- CVE-2016-4476
- CVE-2015-8041
Fixed envrams exposed issue. Thanks to Quentin Kaiser from IoT Inspector Research Lab contribution.
Please unzip the firmware file first then check the MD5 code.
MD5: d507027a6b5b203d5d70be06e5f68abf
DOWNLOAD
SHOW MORE DESCRIPTION
Version 3.0.0.4.386.44266
2021/07/02 71.02 MBytes
ASUS RT-AX88U Firmware version 3.0.0.4.386.44266
1. Fix AiMesh issues
2. Improve system stability
3. Fix WAN DNS setting cannot setup LAN side pihole server.
4. Fixed DoS vulnerability from spoofed sae authentication frame. Thanks for Efstratios Chatzoglou, University of the Aegean, Georgios Kambourakis, European Commission at the European Joint Research Centre, and Constantinos Kolias, University of Idaho.
Please unzip the firmware file first then check the MD5 code.
MD5: 43efe8f59357d53b7b51bc0036d905f2
DOWNLOAD
SHOW MORE DESCRIPTION
Version 3.0.0.4.386.42820
2021/05/10 70.36 MBytes
ASUS RT-AX88U Firmware version 3.0.0.4.386.42820
- Fixed IoT devices connection issues.
- Fixed the fragattacks vulnerability.
Please unzip the firmware file first then check the MD5 code.
MD5: de715b28c7404eed4f5ee6bc007f9342
DOWNLOAD
Version 3.0.0.4.386.42819
2021/04/29 70.06 MBytes
ASUS RT-AX88U Firmware version 3.0.0.4.386.42819
1. Fix VPN GUI issues.
2. Fix WAN connection issues. Special thanks to Yulei Zhang's contribution.
3. Fix AiMesh related bugs.
4. Minor GUI issue fixes.
5. Upgrade dropbear to version 2020.81
6. Fix buffer overflow vulnerability
7. Fix slowloris denial of service attack.
8. Fix authentication bypass vulnerability.
Please unzip the firmware file first then check the MD5 code.
MD5: 47dcbe3ac7084a656304b269a0dd9b0f
DOWNLOAD
SHOW MORE DESCRIPTION
So obviously, 45581, which is newer than the newest release I posted here, contains all of these previous fixes. What else has happened since then? Well, only one single release (and there's a chance that at least some of these are also present in 45581), and it contains this fairly short changelog:
Code:
Firmware
Version 3.0.0.4.386.45898
2021/10/06 71.51 MBytes
ASUS RT-AX88U Firmware version 3.0.0.4.386.45898
1.Fixed AiMesh web page multi-language issues.
2.Fixed Let's encrypt issues.
3.Fixed Stored XSS vulnerability.
4.Fixed CVE-2021-41435, CVE-2021-41436.
Thanks to Efstratios Chatzoglou, University of the Aegean
Georgios Kambourakis, European Commission at the European Joint Research Centre
Constantinos Kolias, University of Idaho.
5.Fixed Stack overflow vulnerability. Thanks to Jixing Wang (@chamd5) contribution.
6.Fixed information disclosure vulnerability .Thanks to CataLpa from DBappSecurity Co.,Ltd Hatlab and 360 Alpha Lab contribution.
Please unzip the firmware file first then check the MD5 code.
MD5: 41ddf19e04b4749ff8c1cea00cb5777d
DOWNLOAD
SHOW MORE DESCRIPTION
So, out of this list, which security fix are you sorely missing that's causing you to suddenly go all panicky?
If the fact that (for obvious reasons) I cannot provide Asus's fixes the very same day they release them themselves, then by all means, switch to the stock firmware.
And when they release Curl security fixes 6 months after me, then you can panic some more, and switch again to my firmware.
Seriously, this constant "OMG SECURITIZE, YOU ARE BEHIND ASUS" panic
has to stop, I'm sick and tired of hearing the same tired song year after year.
Surely it would have made more sense for Asus to provide you with GPL from an already tried, tested and released version [for e.g. GPL 386_45898]??. Issues that members are raising here with Alpha2 seem to be echo's from past, already rectified errors.
Dude, the vast majority of the raised issues (PPPoE, VPN page, etc...) were all the usual merge-related issues that come from me having to merge a 1.2 GB source tarball on top of my code with zero idea as to what changed and why. They have nothing to do with things Asus has fixed, they are just the usual issues that
will happen whenever I merge a new GPL, and I am still in the alpha stage - not even in beta stage yet. And the few wifi-related complains? Look at every single past release, there are
always people claiming that "OMG new release completely broke my wifi!". And not a single time have I been able to reproduce any of the reported wifi issues. Same thing again with 45581, my wifi is rock-solid ever since I started running it last week.
Chill out...