Skip to content

Security: decoderman/AM-Reaper

Security

SECURITY.md

Security Policy

This project exists to harden the RT-BE Series firmware — RT-BEXXU (primary, hardware-validated) plus the RT-BE86U, RT-BE88U, GT-BE98, and GT-BE98 Pro siblings (all BCM4916 / WiFi 7), so security reports are very welcome.

Scope

  • In scope: the changes in this repo — everything under patches/ — and the published reaper images (GitHub Releases), including both build variants (Standard and _MCP). That includes regressions introduced by the hardening itself, and the Reaper-authored subsystems (Hardware QoS, Traffic Analyzer, and the optional read-only LAN-only AI Advisor / MCP server — its arming, LAN-only binding, token auth, and secret redaction are all fair game).
  • Out of scope: bugs in stock Asuswrt-Merlin or ASUS's GPL drop that this project hasn't touched — report those upstream to RMerl/asuswrt-merlin.ng or ASUS. (If a stock bug is remotely/LAN-reachable on any RT-BE Series model, we still want to hear about it — fixing that class of bug is the point of this fork. Base-firmware findings are handled by coordinated disclosure; a recent example is the openssl passwd class-fix reported under ASUS PSIRT case 1006563.)
  • The proprietary Broadcom/ASUS blobs are a documented residual risk (see docs/REAPER-FIXES.md); reports there are appreciated but may only be addressable by mitigation, not by patching the blob.

Reporting

Email theunbounddeveloper@outlook.com with:

  • the affected patch/file or image version (RT-BEXXU_…_reaper_…),
  • reproduction steps or a PoC,
  • whether the issue is reachable from WAN, LAN, or only with authentication.

Please use email rather than a public issue for anything exploitable. You'll get a response as soon as practical; fixes land as new numbered patches and a new release image.

Threat model

The project's bar: only physical access should be able to compromise the device. Anything remotely or LAN-reachable that breaks that bar is a valid, wanted report — see docs/PROJECT.md for the full threat model.

There aren't any published security advisories