This project exists to harden the RT-BE Series firmware — RT-BEXXU (primary, hardware-validated) plus the RT-BE86U, RT-BE88U, GT-BE98, and GT-BE98 Pro siblings (all BCM4916 / WiFi 7), so security reports are very welcome.
- In scope: the changes in this repo — everything under
patches/— and the publishedreaperimages (GitHub Releases), including both build variants (Standard and_MCP). That includes regressions introduced by the hardening itself, and the Reaper-authored subsystems (Hardware QoS, Traffic Analyzer, and the optional read-only LAN-only AI Advisor / MCP server — its arming, LAN-only binding, token auth, and secret redaction are all fair game). - Out of scope: bugs in stock Asuswrt-Merlin or ASUS's GPL drop that this project hasn't touched — report those upstream to RMerl/asuswrt-merlin.ng or ASUS. (If a stock bug is remotely/LAN-reachable on any RT-BE Series model, we still want to hear about it — fixing that class of bug is the point of this fork. Base-firmware findings are handled by coordinated disclosure; a recent example is the
openssl passwdclass-fix reported under ASUS PSIRT case 1006563.) - The proprietary Broadcom/ASUS blobs are a documented residual risk (see
docs/REAPER-FIXES.md); reports there are appreciated but may only be addressable by mitigation, not by patching the blob.
Email theunbounddeveloper@outlook.com with:
- the affected patch/file or image version (
RT-BEXXU_…_reaper_…), - reproduction steps or a PoC,
- whether the issue is reachable from WAN, LAN, or only with authentication.
Please use email rather than a public issue for anything exploitable. You'll get a response as soon as practical; fixes land as new numbered patches and a new release image.
The project's bar: only physical access should be able to compromise the device. Anything remotely or LAN-reachable that breaks that bar is a valid, wanted report — see docs/PROJECT.md for the full threat model.