Nicholas TongASUS RT-AX86U Pro router

27 / 46

the gaming router problem

4 min read 988 words

A black ASUS dual-band wireless router with four antennas, photographed from the front

In May 2025, CISA and MS-ISAC put out an advisory about attackers working over ASUS routers, and the part that stayed with me was not the exploit. It was the persistence. The attackers logged in, flipped Telnet and SSH flags in the router's config, added a port number so unusual that traffic to it was basically a signature, and on some boxes showed a fake firmware update page with a password field on it, so the owner would hand over the admin credential themselves. I read that advisory at lunch, then spent my evening checking NVRAM variables on the ASUS router in my closet, looking for those exact tells. The router was clean. The evening was not relaxing.

The router in question is the RT-AX86U Pro, ASUS's dual-band Wi-Fi 6 box in the AX5700 class, the middle child between the RT-AX86U and the RT-AX88U Pro. Dong Knows Tech wrote the clearest explanation of that confusing family back in December 2022, and RTINGS has a full test of the Pro with the same conclusion I reached in my hallway: it is a very good general-purpose router wearing a gaming costume.

the part everyone gets wrong

People buy gaming routers for the RGB and the joystick icon, and then they get something much more interesting and much riskier than they priced in. A modern ASUS router is not a router. It is a small always-on server with a VPN stack, a USB port, a cloud file service, a mobile app, and a security feed from Trend Micro. Every one of those is a feature. Every one of them is also an open door you have to walk over to and close by hand.

The other thing people get wrong is the update story. There is no auto-update on stock ASUSWRT firmware worth trusting. Updates arrive when you log in to the web interface and click, and most people do not log in to a router web interface after week one. The May 2025 advisory found most victimized routers unpatched. That is not a coincidence, that is the design of the market.

the mechanics

Hardware first, because this is where the Pro earns its suffix over the plain RT-AX86U: a faster CPU, and a 2.5Gbps networking port that you can assign to WAN or LAN, next to the gigabit WAN port, four gigabit LAN ports with one marked as a gaming port, and two USB ports for storage or a modem. The 5GHz radio supports 160MHz channels, and in my brick-heavy house it covered the whole first floor on its own, which I did not expect from one box.

The real mechanic, and the reason I bought this thing, is the firmware ecosystem. ASUS stock is closed, but the box is well supported by asuswrt-merlin, a community firmware that keeps ASUS's hardware support and fixes the parts of the stock experience that make a security person itch. On Merlin I get proper control of DNS, per-device VPN routing, scheduled reboots, and no cloud app requirement. The flash took twenty minutes, including the fifteen I spent reading the changelog, which is the correct ratio.

The security features are the part I want you to look at sideways. AiProtection, the Trend Micro-powered layer, is good marketing and a real feed, and it also sends scan data upstream and wants the router to be online for it. I run it off. I would rather own my DNS filtering and read my own logs than outsource the judgment to a feed that cannot see my network's shape.

where it breaks

AiCloud. ASUS's personal cloud feature has been the box's most repeated security embarrassment for over a decade, and it was the surface in the May 2025 advisory. Here is my confession with specifics: I ran AiCloud enabled for about a year because a family member wanted to grab files off a USB drive, and I turned it off the week the advisory landed and moved the share to the NAS where it should have lived. Nothing happened to me. I do not consider that a defense, I consider it luck with a lag time.

Then the account gravity. The mobile app wants an ASUS account, the web UI nags about AiMesh and app setup, and some firmware pushes push you toward cloud services. Every one of those handshakes is a place where your router's configuration, your client list, and your public IP end up on somebody else's server, and the May 2025 incident list is what happens when the door into the box itself fails. Your router is the one device that can see every device you own. It should be the least cloud-connected thing in the house, not the most.

And the boring limits. One 2.5G port means your multi-gig plans live or die at the switch. The dual-band design shares airtime like every dual-band design. The guest networks work but the VLAN story on stock firmware is thin, and Merlin only patches what ASUS ships underneath, so a driver bug in a closed blob is a driver bug until Broadcom cares.

what to do

  1. Log in to your ASUS router tonight and turn AiCloud off unless a named person needs it for a named reason.
  2. Check that remote web access from the WAN is disabled, then set a unique admin password anyway.
  3. Update on a schedule you own, and if the box supports Merlin, flash it once and subscribe to its release notes.
  4. UPnP off. Gaming consoles negotiate what they need; everything else can be explicit.
  5. If you want to check for the May 2025 attack tells, the variables to look for are the Telnet and SSH flags and any port forward you did not create.

The joystick icon is decoration. The NVRAM is the truth.

Run the check tonight, all five items, and write down what you found. A router you cannot describe is a router somebody else is describing for you.