What's new

BIG issue with ASUS routers killing network with upload flood

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Armand28

Occasional Visitor
AXE16000 running Merlin firmware, AT&T fiber internet connection. The system status page reports HUGE (40MB/S!!! On a 1Gbit connection!) upload spikes, and all 4 cpu cores spike and my connection to the internet drops. I have a HomeAssistant monitor that pings google every 60 seconds and it reports drops while these spikes happen. I’m not the only one having this issue and I cannot figure out what it is. The system status page reports the spike, yet the traffic analyzer page and the QOS monitor doesn’t show any device using that traffic. It’s a mystery. I reboot the router and it’s good for a bit, but then it starts up again. It started about a week ago, and in the thread I linked above others had it started the same time. I’m creating this post in the hopes someone from ASUS sees it! I work from home and if my router doesn’t work I’m hosed.

Screenshots:
As you can see, my upload speeds are WAY over what my internet connection is, and I show outages when the spikes get bad so it’s definitely impacting performance. I have two other routers set as repeaters and during these spikes none of them are showing traffic like that, and since traffic analyzer isn't seeing it either it has to be originating from the router, not any attached devices. The fact that it is happening on both Merlin and ASUS firmware and multiple models of router leads me to suspect DDNS, which I'll try disabling next. I cannot think of any other common denominator, but others have tried it and it still doesn’t work.

It’s impacting multiple models of router, running both Merlin and ASUS firmware, across multiple ISPs. It just started a week or so ago for me, and others in the thread I link above had it start around the same time. I really hope someone from ASUS is working on this, I hate to throw out a $700 router but if I cannot use it to work I’m hosed!
 
Last edited:
You are the 4th or more person to recently have what seems to be a similar issue as you read in the other thread. It will be interesting to see if more people have this issue. I'm keeping an even closer eye on my usage.
 
Do you have any AiCloud services enabled?
They were enabled by default and I have disabled them while troubleshooting. Didn't matter much to me as I had never actually used them. We have found that this issue is quite widespread at this point and due to malware.

EDIT: I don't know how it was enabled since I don't remember doing it myself. I've only ever seen it enabled on this router and the last 2 ASUS routers I've had during the previous 12+ years. Everyone else seems to not have it enabled by default so I was probably wrong about the default setting.
 
Last edited:
They were enabled by default and I have disabled them while troubleshooting. Didn't matter much to me as I had never actually used them. We have found that this issue is quite widespread at this point and due to malware.
It is suspected the malware could be using the AiCloud services. Either as a vector or enabling it to run something it needs. Also as far as I know AiCloud is not enabled by default. It hasn’t ever been on the three ASUS routers I’ve had.
 
Last edited:
I think your router is now part of a botnet. I had the same problem since October 20th.
SSH -> top shows the /var/Sofia process that is hogging the CPU. And the WAN access process.
87cdbc2e-6a4a-49ea-a3d9-22799a9eb270.png

Clipboard+3.png

More information here - https://www.bitdefender.com/files/N...per-DarkNexus-creat4349-en-EN-interactive.pdf

I reset my router several times. The last time was through SSH
rm -rf /jffs/*
rm -rf /data/*
nvram erase
nvram commit
sleep 3
reboot

And DISABLE web access from WAN to login page !!!
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top