Release Notes for Version 6.6.1
Release Date: April 24, 2026
Warning
- Due to the significant changes introduced in the 6.4.x, 6.5.x, and 6.6.x releases, extensive testing of the new firmware is strongly recommended before deploying it in operational environments, especially when upgrading from version 6.3.x.
- Several Router App functions have been integrated directly into the firmware since version 6.6.0. Existing Router App configuration is not converted during the upgrade. Users must reconfigure the corresponding functionality in the firmware and then uninstall the related Router Apps. The same feature must not be enabled simultaneously in both the firmware and the original Router App.
Added
- Added VXLAN tunnel support, allowing the creation of isolated Layer 2 networks across multiple sites.
- Added support for additional Dynamic DNS protocols, extending traditional DynDNS:
- Added HTTPS transport support to DynDNS, with an optional custom CA.
- Added support for RFC 2136 DDNS (except for ICR-20,24,25/2600).
- Renamed DynDNS menu and status items to Dynamic DNS.
- Added LLDP (Link-Layer Discovery Protocol) service, enabling discovery of neighboring devices to simplify network management and troubleshooting (except for ICR-20,24,25/2600).
- Added the ability to configure a second Ping IP Address in Mobile WAN Configuration. The SIM will be switched if none of the listed addresses are reachable.
- Extended the GNSS Configuration:
- Added the ability to filter the forwarded NMEA sentences.
- Increased the maximum number of remote targets from 4 to 10.
- Extended the Manage SIM administration:
- Added indication of the selected SIM Card to the Unlock/Unblock SIM and Set SMS Center pages.
- Added command to Switch SIM when Create connection to mobile network is disabled in Mobile WAN Configuration.
- Added Router Apps status page providing a quick overview.
- Added SNMP infoPN (1.3.6.1.4.1.30140.6.12) object providing the Part Number.
- Added Load From File buttons to User's Scripts through the Web GUI and to the Accept/Deny List in WiFi AP Configuration.
- Added new user role Operator. Users with this role can access the Web administration only to manage their credentials. This role is intended for special-purpose Router Apps.
- Extended System Report with a list of NTP Sources.
- Extended
status hwto also display the number of cellular modules, Digital Input/Output, Serial Ports, Bluetooth, and PoE PSE/PD. - Added
digandnsupdatecommand-line tools for DNS operations. - Added
clearandwatchtools to improve command-line operability. - Added support for per-CPU statistics in
top, toggleable via theckey. - Added support for
grepcontext, i.e. arguments-A,-B, and-C. - Added
hostnametool for printing the device hostname. - Added
xterm-256colorterminfo for improved operation of command-line tools. - Added support for ICR-2454 with Telit FE910C04-WWD.
Changed
- Extended the Network Status page:
- Extended Backup Routes with WAN IP and IPv6 addresses.
- Added LLDP Neighbors list (except for ICR-20,24,25/2600).
- Moved link to Connections list to the main menu.
- Enhanced user experience of the Web Administration:
- Moved the Factory Reset button from the Reboot Now page to a standalone page under Restore Configuration.
- Removed the briefly displayed User has been logged in page, so the login is faster. This may impact users accessing the Web Administration via automated tools such as
curl. - Extended the address fields in Firewall Configuration so the entire IPv4 address range or an IPv6 address can be viewed.
- Changed IPsec Tunnel Configuration and behavior:
- Changed default IKE Protocol from IKEv1 to IKEv1/IKEv2.
- Enabled IKE Reauthentication also for IKEv1/IKEv2 protocol.
- Modified IPsec rekeying and reauthentication times so that the configured Key Lifetime is strictly the time for rekeying, and IKE Lifetime is strictly the time for reauthentication.
- Increased default Key Lifetime from 3600 to 7200 sec (2 hours), and default IKE Lifetime from 3600 to 28800 sec (8 hours).
- Renamed Rekey Margin to Lifetime Margin, and Rekey Fuzz to Lifetime Fuzz.
- Removed the checkbox Use Custom CA Certificate in Automatic Update. To use a custom certificate, simply fill the CA Certificate field.
- Optimized Ethernet performance:
- Replaced the default
pfifo_fastroot queuing discipline withfq_codelto improve latency and fair queueing. Because a root qdisc already exists, users relying ontc qdisc addmust now usetc qdisc replace. - Improved CPU load distribution and packet processing efficiency on all ICR-4xxx.
- Replaced the default
- Decreased the maximum length of Router Identification in GNSS Configuration from 128 to 70 characters for better compliance with the NMEA standard.
- Decreased the maximum size of the SSH Public Key in User Management to 16 KiB.
- Changed SNMP OID of ICR-2452 routers to 1.3.6.1.4.1.3014.1.2452. Previously the OID was the same as for ICR-447x (1.3.6.1.4.1.3014.1.89).
- Removed Web pages and
statuscommands that are not valid for the specific product, e.g.status moduleis now not available on LAN routers. - Upgraded the ca-certificates bundle to the version from 2025-12-02.
- Upgraded the wireless regulatory database to the version from 2026-02-04, and the country codes list (UN M49) to the version from 2026-03-09.
- Upgraded OpenSSL to version 3.5.5 to address the CVE-2025-15467 (critical), CVE-2025-69419, and CVE-2025-69421 (high), CVE-2025-15468, CVE-2025-66199, CVE-2025-69420, and CVE-2026-22796 (medium).
- Upgraded OpenVPN to version 2.6.19 to address CVE-2025-13086 (high).
- Upgraded Net-SNMP to version 5.9.5.2 to address CVE-2025-68615 (critical).
- Upgraded U-Boot on ICR-41xx/42xx to version 2024.10.
Deprecated
- WiFi Encryption algorithms WEP and TKIP will be removed in a future release due to known security flaws that allow attackers to decrypt traffic and gain unauthorized access. Users should migrate to AES.
Fixed
- Fixed MBIM communication failure on ICR-4261 with RM520N-GL revision RM520NGLAAR03A03M4G_A0.300.A0.300.
- Fixed stability of IPsec tunnels with multiple subnets when Separate Child SA for Each Subnet is enabled.
- Fixed display of Signal Min and Signal Max values in SIM Statistics.
- Fixed ability to report GNSS information via SNMP.
- Fixed firewall configuration when NAT enables remote SSH access and the SSH Configuration defines a Port other than 22.
- Fixed SSH service behaviour after opening three concurrent unauthenticated connections to match the standard behaviour for
MaxStartups 3:60:6. - Fixed minor issues in the Web Administration:
- Fixed the Network Type selection in the Mobile WAN Configuration to display supported technologies only.
- Fixed display of LTE bands > 100 in Mobile Network Information.
- Fixed saving of Registration Timeout for the second SIM in the Mobile WAN Configuration.
- Fixed display of SHA-1 Authentication in SNMP Configuration after upgrading from a previous version.
- Fixed update of NTP Configuration on LAN routers.
- Improved reliability of saving the configuration just before device shutdown.
- Fixed detection of a full Model name for EC25/EG25 variants.
- Fixed Region assignment of ICR-3201 (Worldwide) and BB-SL302 FM (North America).
- Fixed Telit GNSS to also send GLL, GSV, and VTG NMEA sentences.
- Fixed default HTTPS certificate to include
CA:TRUEand allowkeyCertSign. - Fixed Configuration Reset to reset also the
/etc/groupfile. - Fixed double reboot in some situations during Emergency Reset.
- Fixed Bluetooth discovery stall in some situations.
- Fixed WiFi and GNSS auto-detection in OEM products manufactured before 2019.
- Fixed usage help of the
gsmpwrcommand. - Fixed creation of Crash Dumps from privileged processes.