speedingcheetah
Senior Member
AC56U
Lots of stuff in this one:
ASUS RT-AC56U Firmware version 3.0.0.4.374.5656
Security related issues:
1. Fixed remote command execution vulnerability
2. Fixed parameters buffer overflow vulnerability
3. Fixed XSS(Cross Site Scripting) vulnerability
4. Fixed CSRF(Cross Site Request Forgery) vulnerability
5. Added auto logout function. The timeout time can be configured in - Administration--> System
6. Included patches related to network map. Thanks for Merlin's contribution.
7. Fixed password disclosure in source code when adminstrator logged in.
8. Changed OpenSSL Library from 1.0.0.b to 1.0.0.d. Both OpenSSL versions are not vulnerable to heartbleed bug.
Others:
1. Added universal beamforming to enhance the wireless speed for non 802.11ac devices
2. Fixed IPTV related issues.
3. Modified the 3G/LTE dongle setting process in quick internet setup wizard.
4. Fixed the Cloud sync problem
5. Fixed Parental control check box UI issues.
6. Modified the FTP/ Samba permission setting UI
7. Modified media server setting UI
8.Samba/ media server/ iTunes server name can be changed.
9. Dual wan fail over now support fail back
10. Fixed wake on lan magic packet sending issue.
11. Fixed false alarm for samba and ftp permission.
12. Fixed IPv6 related issues.
13. Supported HFS+
14. Supported Time machine
---
Special thanks for David and Joaquim Brasil de Oliveira’s research
CVE-2014-2719 http://dnlongen.blogspot.com/2014/04/CVE-2014-2719-Asus-RT-Password-Disclosure.html
Cross Site Scripting: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-2925
Remote Command Execution: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-5948
http://dlcdnet.asus.com/pub/ASUS/wireless/RT-AC56U/FW_RT_AC56U_30043745656.zip
Lots of stuff in this one:
ASUS RT-AC56U Firmware version 3.0.0.4.374.5656
Security related issues:
1. Fixed remote command execution vulnerability
2. Fixed parameters buffer overflow vulnerability
3. Fixed XSS(Cross Site Scripting) vulnerability
4. Fixed CSRF(Cross Site Request Forgery) vulnerability
5. Added auto logout function. The timeout time can be configured in - Administration--> System
6. Included patches related to network map. Thanks for Merlin's contribution.
7. Fixed password disclosure in source code when adminstrator logged in.
8. Changed OpenSSL Library from 1.0.0.b to 1.0.0.d. Both OpenSSL versions are not vulnerable to heartbleed bug.
Others:
1. Added universal beamforming to enhance the wireless speed for non 802.11ac devices
2. Fixed IPTV related issues.
3. Modified the 3G/LTE dongle setting process in quick internet setup wizard.
4. Fixed the Cloud sync problem
5. Fixed Parental control check box UI issues.
6. Modified the FTP/ Samba permission setting UI
7. Modified media server setting UI
8.Samba/ media server/ iTunes server name can be changed.
9. Dual wan fail over now support fail back
10. Fixed wake on lan magic packet sending issue.
11. Fixed false alarm for samba and ftp permission.
12. Fixed IPv6 related issues.
13. Supported HFS+
14. Supported Time machine
---
Special thanks for David and Joaquim Brasil de Oliveira’s research
CVE-2014-2719 http://dnlongen.blogspot.com/2014/04/CVE-2014-2719-Asus-RT-Password-Disclosure.html
Cross Site Scripting: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-2925
Remote Command Execution: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-5948
http://dlcdnet.asus.com/pub/ASUS/wireless/RT-AC56U/FW_RT_AC56U_30043745656.zip
Last edited: