Home » Script to decode Asus router configuration backup file

Script to decode Asus router configuration backup file

by Vlad Drumea
19 comments 2 minutes read

I’ve been messing around with routers this weekend, and I’ve decided to write a PowerShell script to decode Asus router configuration backup files.

The script is inspired by this Bash script that I’ve used in my previous blog post.

You can find the PowerShell script in my Asus-Router-Config-Decoder GitHub repository.

Why?

Because I wanted to understand how Asus routers encode and decode their configuration backups.
I already had the previously mentioned Bash script as a starting point.
And I considered that it would be a nice PowerShell exercise, since I haven’t done any work on PSBlitz for a while.
The added bonus to this is that the resulting PowerShell script is faster than the Bash script I used as the inspiration for it.

What it does?

  1. decodes the provided .cfg file
  2. writes the decoded content to a text file
  3. writes DHCP client list to a pipe-delimited text file

It also outputs the following to the console:

  • Web GUI admin username and password
  • Wi-Fi network names (SSIDs)
  • Wi-Fi passwords (WPA PSKs)
  • PPPOE credentials

    At the moment, the script has been successfully tested with the following Asus router models:

    • Asus RT-BE88U
    • Asus RT-AX86U Pro
    • Asus RT-AC86U
    • AX58U
    • RT-AX55

    Feel free to leave a comment with the Asus router models you’ve used this script to decode their configuration files.

    How to use it to decode Asus router backup files?

    Execute it in PowerShell (version 5.1 and up) and pass the name of the .cfg Asus backup file you want to decode.

    Usage examples

    If the configuration file you want to decode is in the same directory as the script:

    If the script is in a different directory from the one where the Asus router configuration file is:


    Conclusion

    I just figured I’d share the result of my weekend PowerShell exercise in case anyone might need it to decode their Asus router configuration backup.

    If you’re interested in more networking related uses for PowerShell, check out this post about doing a ping sweep using PowerShell.

    You may also like

    19 comments

    Kevin Peters December 11, 2024 - 17:58

    Thank you, got me out of a pickle!

    Reply
    Vlad Drumea December 31, 2024 - 16:29

    I’m glad it was useful!
    Care to mention the model of your router in case it’s not one already on the list?

    Reply
    Andrew July 18, 2025 - 01:11

    Thank you worked perfect for AX58U config file

    Reply
    Vlad Drumea July 18, 2025 - 19:42

    Awesome! Thank you for mentioning your router model!

    Reply
    Michel August 8, 2025 - 02:37

    Hello, this works perfectly as well on the RT-AX88U.
    Actually I’m looking for the inverse operation.
    I would like to automate the backup of the config (eg. every week or so) for now I can get the clear version with “nvram show > file” but not the “binary” version. Do you have this PS script as well otherwise I will inspire from this one.
    Thanks.

    Reply
    Michel August 8, 2025 - 14:39

    Edit:
    Actually it’s even RT-AX88U with Merlin.
    For the binary version, nevermind, I found that “nvram save /file” save it as binary
    Thanks.

    Reply
    Vlad Drumea August 15, 2025 - 11:44

    Glad to hear you’ve sorted that out, Michel.

    Reply
    Cirbolya August 13, 2025 - 08:11

    File header check failed.

    RT-AC58U

    Reply
    Vlad Drumea August 15, 2025 - 11:52

    Hi Cirbolya,
    The OS of that model might not generate the type of config backup that this script works with, but for testing purposes I’ve modified the script a little to allow you to skip the header check part.
    All you need to do is grab the latest version of the script from GitHub and run it with -SkipHeaderCheck at the end of your command.
    Example:
    PS>.\Decode-AsusRouterConfig.ps1 ‘C:\Users\SomeUser\Documents\Settings_RT-AX86U Pro.CFG’ -SkipHeaderCheck

    Reply
    nez October 7, 2025 - 23:21

    Hey,
    Thanks for sharing your script to decode asus config settings.
    I have the Asus TUF GAMING AX6000 and unfortunately it doesn’t work, it says “Data length check failed”
    Any idea what the cause is?

    Reply
    Stu May 23, 2026 - 20:31

    It worked for my RT-AX55. Thank you.

    Do you have a script to convert the result back to an ASUS CFG file that the router can upload? I have a large number of ports forwarded and changes are painful as the list on the router cannot be sorted to easily find the desired service name or ip address to be altered. My thought is to rearrange your output file’s list of services to import back into the router. Note that the converted output is helpful (though less convenient) even if you do not have what I ask as I can use a text editor to search for and see the position in the text file.

    Reply
    Vlad Drumea May 23, 2026 - 20:59

    Hi Stu,
    At a glance, this should be doable as long as you have both the original CFG file (which might not actually be necessary, but I need to run some tests to be sure) and the decoded version with your changes.
    Luckily, I have a spare test router which I can use for this.
    I’m juggling a few things at the moment, but I’ll try and have something usable sometime next week.

    Reply
    Stu May 24, 2026 - 04:17

    Wow – that was an amazingly fast response! Your generosity of your time to produce a script is greatly appreciated, and no hurry as you have more to do than this. I used a text editor to extract and format the “vts_rulelist” to a csv file that I can sort as needed. Since you are willing to create a script to convert your decoded file back to CFG there is more I can do for myself and potentially for others. Would you be so kind as to send an email to which I can respond? Not appropriate to discuss details here I think – I will outline a program I can write to manipulate your converted file which can then be converted to CFG with your new script. That program could then be placed at github for others to use.

    Reply
    Vlad Drumea June 3, 2026 - 22:14

    Hi Stu,
    Sorry for the delay, had a bit of a hectic week.
    I’ll send you an email shortly to the address used for your comments.

    Reply
    Stu June 5, 2026 - 20:55

    Hi Vlad,

    No problem on delay – I replied to email.

    Forgot to say in email “I understand if you decide ‘no'”

    ryan September 23, 2026 - 06:16

    Hi Stu, i too have a similar issue with lots of config in a router and do not want to re configure.
    Did you manage to write the script to recompile the decoded data back into a cfg file?

    Cheers.

    Reply
    Kevin Gilchrist May 25, 2026 - 22:11

    Didn’t work for Zenwifi XT9
    Tried having claude decode it but not luck there either.

    Reply
    ryan September 22, 2026 - 10:51

    Works with ax11000 for all but not passwords or wifi keys

    Reply
    ryan September 23, 2026 - 06:00

    Actually, can confirm working with Asus BD4 and AX-11000.
    I must have clicked the box to remove passwords.

    Reply

    Leave a Comment

    * By using this form you agree with the storage and handling of your data by this website.

    This site uses Akismet to reduce spam. Learn how your comment data is processed.