QUOTE(3antz @ Jan 11 2016, 09:13 PM)
Hi, can i know which is the latest firmware for RTN12HP? Via the link on frontpage is 3.0.0.4.376.4018. If I search on Asus it is 3.0.0.4.378.9443 ? Which is the correct version? tnx
Was wondering the same myself... I just dug out my old 12 HP after having some problems with the D-link AC 750 (Dir 816). The answer to your question will depend on what Revision of RTN 12HP you got.. If you have the B1 you can flash the latest which is 3.0.0.4.378.9443.
This leads to my question addressed to ASUS MY.. Both revision of the router started of using same firmware version numbers, with the first upgrade to 4018 fixing the same issues.. The B1 then got 3 more updates to the current 9443 with numerous security and other upgrades... Does this mean that the non B1 revision is still lacking the following??
ASUS RT-N12HP_B1 Firmware version 3.0.0.4.378.7449
Security fixes
- Enhanced the login authentication strength and fixed related issues.
- Forced administrator to change the default password "admin" in internet setup wizard.
- Added protection mechanism for GUI login brute-force attack for login username and password.
- Administrator can assign a specified IP to login GUI in Administration > System > "Allow only specified IP.
- Fixed CSRF and XSS vulnerability when router is in default status.
- Fixed infosvr security issue.
ASUS RT-N12HP_B1 Firmware version 3.0.0.4.378.9165
Security Fixes
- Fixed CVE-2015-6949 buffer overflow issue, special thanks for Elvis Collado at Praetorian.
- Fixed Web server Accept-Language buffer overflow, special thanks for Elvis Collado at DVLabs.
- Fixed Web server URL handler buffer overflow special thanks for Elvis Collado at DVLabs.
- Fixed CSRF and XSS vulnerability.
- Fixed infosvr security issue
- Enhanced router login password and wireless password (WPA2) strength check method to against brute-force attack.
- Reject administrator to set too easy to guess login and wireless password to avoid brute-force attack.
ASUS RT-N12HP B1 Firmware version 3.0.0.4.378.9443
Security fixes:
- Fixed User-Agent buffer overflow.
- Fixed null ptr dereference in https issue.
- Fixed buffer overflow issues.
- Modified brute-force protection mechanism in router login page.
- Fixed CVE-2015-6949 buffer overflow issue.
- Fixed Web server Accept-Language buffer overflow.
- Fixed Web server URL handler buffer overflow.
- Fixed CSRF and XSS vulnerability.
- Enhanced router login password and wireless password(WPA2) strength check method to against brute-force attack.
- Reject administrator to set too easy to guess login and wireless password to avoid brute-force attack.
- Fixed CSRF and XSS vulnerability when router is in default status (user does not set the router yet)..
As you can see there has been extensive work to get the B1 Patched and updated....
Is the non B1 Rev safe to use without all these security updates??
Thanks for your help
Roger