OpenWrt update 25.12.5

A minor release of the OpenWrt 25.12.5 distribution, developed for network devices such as routers, switches, and access points, has been released. OpenWrt supports over 2200 devices and offers a build system that simplifies cross-compilation and the creation of custom builds. These builds allow for the creation of ready-to-use firmware with a desired set of pre-installed packages, optimized for specific tasks. Ready-to-use builds have been published for 41 target platforms.

Among the changes:

  • Added device support:
    • ipq40xx: Linksys MR9000
    • mediatek: GL.iNET GL-MT3600BE, Huasifei WH3000R (NAND), JioRouter AX6000 (JIDU6101), netis EAP930 V1, netis MEX605, TP-Link F65 v1, Zbtlink ZBT-Z8106AX-S
    • mvebu: Zyxel NAS326
    • ramips (mt76x8): Cudy WR300 v1
    • ramips (mt7621): IO DATA WN-AX2033GR2
  • Added new build options for previously supported devices on Mediatek chips: Qihoo 360T7, Creatlentem CLT-R30B1 and Bazis AX3000WM.
  • Corrections have been made related to the operation of the platforms:
    • ath79: MikroTik AR8216/AR8236/AR8316
    • mediatek: Wavlink WL-WN536AX6 rev A, Qihoo 360T7
    • ramips: PAX1800 Lite, Cudy LT300 v3
    • rtl8367b: RTL8367S-VB
    • mvebu: uDPU / eDPU
    • ipq806x: AP3935
    • airoha: an7581
  • Added a new handler for displaying network interface activity via LED indicators on devices.
  • Fixes for stability issues in odhcpd, odhcp6c, ubus, rpcd, uhttpd, umdns, uclient, and fstools.
  • Kernel versions have been updated Linux 6.12.94 (was 6.12.87), OpenSSL 3.5.7, wireless-regdb 2026.05.30, dnsmasq 2.93, util-linux 2.41.5.
  • Remotely exploitable vulnerabilities in network services enabled by default have been fixed:
    • odhcpd (CVE-2026-53921) - Remote buffer overflow exploitable via a specially crafted DHCPv6 request.
    • LuCI - code substitution in the web interface by returning a specially formatted hostname via DHCPv6.
    • luci-app-tailscale-community — allows a user with access to the web interface to execute commands with root privileges.
    • uhttpd (CVE-2026-55612) - Injecting into other people's requests.
    • cgi-io - ACL bypass to read files owned by root.
    • ead (Emergency Access Daemon) is a DoS attack that occurs before authentication.
    • accumulated vulnerabilities in the kernel Linux, OpenSSL, musl and Dropbear SSH.

    Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster