ASUSWRT-MERLIN

Other ASUSWRT-MERLIN 3004.388.11

No permission to download
- NOTE: AiCloud has been removed from Asuswrt-Merlin due
to its poor security track record. This also includes
cloud syncing features such as Asuswebstorage or
Dropbox syncing with USB folder. Use a VPN if you
need secure remote access to your data.

- NOTE: For developers, the Tomato legacy files (tm*.*)
are no longer included with the webui. Please
update your addon pages accordingly.

- NEW: Redesigned Traffic Monitor pages.
- Uses Chart.js for Realtime and Last24 pages
- Removes legacy Tomato code
- Last 24 can be zoomed in and panned (mouse wheel
and pinch-to-zoom gestures are both supported)
- Realtime and Last 24 now show as bits/s instead
of bytes/s
- Settings moved from the tab to the dropdown menu
- Removed NVRAM database location option and added
JFFS. Also removed rarely used start-of-month
setting.

- UPDATED: Merged GPL 388_25575.
- UPDATED: OpenVPN to 2.6.17.
- UPDATED: libcap-ng to 0.8.4 (to be in sync with upstream)
- UPDATED: Dropbear to 2025.89.
- UPDATED: nettle to 3.10.2.
- CHANGED: TrafficMonitor stats can now be saved to JFFS,
and removed support for saving to NVRAM.
- FIXED: IPv6 blocking of DoT servers (dave14305)
- REMOVED: outdated setuprsa.sh script.
- REMOVED: AiCloud support, due to security reasons.
3004.388.10_2 (31-Oct-2025)
- UPDATED: OpenVPN to 2.6.15.
- FIXED: Web server crashing when connecting using the App API,
used by the mobile app and also Home Assistant (Asus).


3004.388.10 (4-Oct-2025)
- NOTE: For developers, please note that the new default branch
is now called "main" - it's what was previously the
3006.102 branch.
The "master" branch has been renamed "master-old", and
is no longer actively used. Due to how the 3006.102
branch diverged, it was easier to do it this way than
to fold back 3006.102 on top of master.
3004.388 remains where 3004.388 models live.
3004.388.10 (4-Oct-2025)
- NOTE: For developers, please note that the new default branch
is now called "main" - it's what was previously the
3006.102 branch.
The "master" branch has been renamed "master-old", and
is no longer actively used. Due to how the 3006.102
branch diverged, it was easier to do it this way than
to fold back 3006.102 on top of master.
3004.388 remains where 3004.388 models live.

- NOTE: Due to numerous webui changes, it's recommended to
force refresh the page after first login, or clear
your browser cache.

- NOTE: Asus has made some security related changes. Password
requirements are stricter, and UPNP is no longer
enabled by default. New password rules were
slightly loosened for Asuswrt-Merlin, repeating
characters are still allowed.

- NEW: Completely redesigned System Log -> Connections page.
- You can now filter the list
- You can set the page to auto-refresh itself
- Public IP addresses can be looked up on
WhatismyIPaddress.com
- Local hostnames will be resolved and shown
- Routed IPv6 connections will be shown

- NEW: Added Control-D servers to DNS-over-TLS
presets (dave14305)
- UPDATED: Merged GPL 388_25523.
- UPDATED: dropbear to 2025.88.
- CHANGED: Setting DNS Director to "Router" will now always
redirect to the router's own IP. Previously it
would redirect to the first DNS server configured
on the DHCP page (which defaults to the router
itself).
If you need DNS Director to redirect to an IP
configured in your DHCP settings, use a Custom DNS
entry in DNS Director. This makes it more consistant
with what the name implies, and was also necessary
for improved Guest Network support.
- CHANGED: Replaced netstat-nat by a fork called netstat-nat-ng.
This fork fixes a number of issues with IPv6 and
field size.
- CHANGED: Optimized performance when refreshing the Sysinfo
page on a network with thousands of tracked
connections.
- CHANGED: Modified the Quick Internet Setup wizard so not
to attempt downloading firmware updates from Asus
(which would fail anyway).
- CHANGED: Tools category renamed System Info.
- CHANGED: Tools -> Other Settings were moved to new tabs
(Administration -> Tweaks, and
Traffic Analyzer -> Settings).
- CHANGED: Moved "Redirect to asusrouter.com" to the new
Tweaks tab, and moved "Enable JFFS Custom Scripts"
to the Basic Config section on the System page.
- CHANGED: Backported Wireless Log hostname retrieval code
from 3006 (based on IP instead of MAC)
- FIXED: DNSDirector "Router" mode would not always work properly
with IPv6 (now uses REDIRECT instead of DNAT, which was
backported from iptables 1.4.19).
- FIXED: Additionnal fix for the status frame missing from
Network Map under certain hostnames.
- FIXED: CVE-2025-9230 in OpenSSL (backport by RSDNTWK).
- UPDATED: miniupnpd to 2.3.8.
- FIXED: CVE-2025-2492 in AiCloud (backport from upstream)
- FIXED: Networkmap system status frame failing to load when
accessing the router with some particular hostnames.
- FIXED: Networkmap client list wordwrapping long hostnames.
- FIXED: webui issue when DDNS set to Custom.
- FIXED: Compatibility issues with IoT devices and WPA2/WPA3
networks (Asus)
3004.388.9 (9-Apr-2025)
- NOTE: BCM4912 models such as the GT-AX6000 have now been
migrated to the 3006 firmware series.

- NEW: (re-added) VPN interface selector on the Speedtest page,
to test a VPN tunnel's throughput.
- UPDATED: Merged GPL 388_25373.
- UPDATED: dropbear to 2025.87.
- UPDATED: OpenVPN to 2.6.14.
- UPDATED: dnsmasq to 2.91.
- UPDATED: miniupnpd to 2.3.7 (20250207 snapshot)
- UPDATED: amtm to 5.2 (decoderman)
- CHANGED: VPN public IP retrieval now uses HTTP instead of STUN,
which should be more reliable through a VPN tunnel.
- CHANGED: Model name will be inserted in the filename of JFFS
backups.
- CHANGED: Improved refresh behaviour of the VPN Status page.
- CHANGED: Set rp_filter mode to "loose" on Wireguard client
interfaces.
Fixes gettunnelip.sh and onboard speedtest.
- CHANGED: Display public IP address for Wireguard clients.
- CHANGED: Make PCP requests also honor the Secure Mode setting
(Self-Hosting-Group)
- CHANGED: Settings/JFFS backup uploads file picker will filter by
file extension.
- CHANGED: Added dhd userspace tool to RT-AX88U and GT-AX11000.
- CHANGED: WAN IPv6 provided as second argument to the ddns-start
script.
- FIXED: CVE-2024-9143 in OpenSSL (Debian backport by RSDNTWK)
- FIXED: Missing icon for the GT-AX11000 on AiMesh page
- CHANGED: VPN killswitch will now only be active if the
VPN client itself is enabled. If you stop/start
the client yourself over SSH, you need to also
update the enabled/disabled nvram setting.
- FIXED: Security issues in AiCloud (backports from Asus)
- FIXED: CVE-2024-2511, CVE-2024-4741, CVE-2024-5535 &
Implicit rejection for RSA PKCS#1 in openssl
(backport from Ubuntu by RSDNTWK)
- UPDATED: dnsmasq to 2.90 (resolves CVE 2023-50868 and CVE 2023-50387).
- FIXED: LACP support was missing on the XT12.
  • Like
Reactions: Whodajoker
386.12_4 (21-Nov-2023)
- UPDATED: openvpn to 2.6.8 (fixes a crash introduced in 2.6.7)
Back
Top