A corrected release of the OpenWrt distribution 25.12.5 has been presented, developed for network devices such as routers, switches, and access points. OpenWrt supports over 2200 devices and offers a build system that simplifies cross-compilation and the creation of custom builds. Such builds allow for the formation of ready-to-use firmware with a desired set of pre-installed packages, optimized for specific tasks. Ready builds have been published for 41 target platforms.
Among the changes:
- Added support for devices:
- ipq40xx: Linksys MR9000
- mediatek: GL.iNET GL-MT3600BE, Huasifei WH3000R (NAND), JioRouter AX6000 (JIDU6101), netis EAP930 V1, netis MEX605, TP-Link F65 v1, Zbtlink ZBT-Z8106AX-S
- mvebu: Zyxel NAS326
- ramips (mt76x8): Cudy WR300 v1
- ramips (mt7621): I-O DATA WN-AX2033GR2
- New build options have been added for previously supported devices on mediatek chips: Qihoo 360T7, Creatlentem CLT-R30B1, and Bazis AX3000WM.
- Corrections related to platform operations have been made:
- ath79: MikroTik AR8216/AR8236/AR8316
- mediatek: Wavlink WL-WN536AX6 rev A, Qihoo 360T7
- ramips: PAX1800 Lite, Cudy LT300 v3
- rtl8367b: RTL8367S-VB
- mvebu: uDPU / eDPU
- ipq806x: AP3935
- airoha: an7581
- A new handler has been added to display network interface activity through LED indicators available on the devices.
- Bug fixes affecting stability have been made for odhcpd, odhcp6c, ubus, rpcd, uhttpd, umdns, uclient, and fstools.
- Updated versions of Linux kernel 6.12.94 (was 6.12.87), OpenSSL 3.5.7, wireless-regdb 2026.05.30, dnsmasq 2.93, util-linux 2.41.5.
- Remote exploitable vulnerabilities in default-enabled network services have been addressed:
- odhcpd (CVE-2026-53921) — remote buffer overflow, exploitable via specially crafted DHCPv6 requests.
- LuCI — code injection into the web interface via returning a specially crafted hostname through DHCPv6.
- luci-app-tailscale-community — allows users with access to the web interface to execute commands with root privileges.
- uhttpd (CVE-2026-55612) — injection into foreign requests.
- cgi-io — bypass of ACL to read files owned by root.
- ead (Emergency Access Daemon) — DoS attack occurring before authentication.
- Accumulated vulnerabilities in the Linux kernel, OpenSSL, musl, and Dropbear SSH.
Source: opennet.ru
