华硕(ASUS)的 ROG Rapture GT-AX6000 路由器的 firmware 在 2025 年 8 月 27 日发布了一个重大更新。
英文的发布说明如下:
ASUS GT-AX6000 Firmware version 3.0.0.6.102_34860
- Version 3.0.0.6.102_34860
- 61.76 MB
- 2025/08/27
- SHA-256 :4787DE9D2DC9A2850F49D74C8C6712AB1932EA485E59D97EC2B97C545D7F73DE
Important: After installing this firmware, we strongly recommend performing a factory-default reset to activate every new security adjustment.
Security Enhancements
- Password Policy Upgrade – Minimum of 10 characters, including at least one letter, one digit, and one special character; disallows consecutive identical characters; hardens defense against brute-force attacks.
- HTTPS on 8443 – Management interface now served over TLS by default.
- UPnP Disabled – Universal Plug and Play starts in the off state for reduced surface exposure.
- AiCloud Authentication Hardening (CWE-287) – Added layered verification.
- Authentication Logic Refactor – Removed redundant code paths for a lean sign-in flow.
- Memory Safety Guard (CWE-476) – Introduced null-reference protections across critical services.
- Enhanced IPsec Parameter Validation – The existing input checks have been hardened.
- Data Exposure Mitigation (CWE-200) – Reinforced controls on sensitive pathways.
- Detailed Audit Trails – Expanded logging within the authentication module.
System Improvements
- Connection Stability – Core algorithms refined for steadier links.
- Scheduling Accuracy – Timed tasks execute reliably under PPPoE, PPTP and L2TP WAN modes.
- Client List Maintenance – Resolved an issue that prevented offline devices from being removed from the client list
如下图:
将它的重要部分用中文编译如下:
重要提示:升级后建议执行一次恢复出厂设置,以启用所有新的安全调整。
安全强化(要点)
- 密码策略升级:至少 10 位,需含字母、数字、特殊字符;禁止连续相同字符,提升抗暴力破解能力。
- 管理端口改为 HTTPS 8443:默认以 TLS 提供管理界面。
- UPnP 默认关闭:减少外部攻击面。
- AiCloud 认证加固(CWE-287)与认证逻辑精简:多层校验,移除冗余路径。
- 内存安全防护(CWE-476):为关键服务加入空指针防护。
- IPsec 参数校验更严格、敏感数据暴露缓解(CWE-200)。
- 审计日志更详尽:认证模块记录范围扩大。
系统改进
- 连接更稳:核心算法优化。
- 定时任务更准:在 PPPoE/PPTP/L2TP 下可靠执行。
- 客户端列表维护修复:可正确移除离线设备。
稍微读一下这个新版本的发布说明就知道它的重要性了。以前的发布都没有要求升级后执行一次设备重置。
另外,重置后,必须使用 https 登录,否则界面渲染会出大问题。
如何配置 https 登录,在后台有详细的说明,看下图:
点击里面的链接可以阅读 ASUS 提供的配置教程。
No comments:
Post a Comment