Release Notes for Version 6.6.2
Release Date: July 28, 2026
This minor release delivers security updates, bug fixes, and improvements to 5G performance.
Warning
- Due to the significant changes introduced in the 6.4.x, 6.5.x, and 6.6.x releases, extensive testing of the new firmware is strongly recommended before deploying it in operational environments, especially when upgrading from version 6.3.x.
- Several Router App functions have been integrated directly into the firmware since version 6.6.0. Existing Router App configuration is not converted during the upgrade. Users must reconfigure the corresponding functionality in the firmware and then uninstall the related Router Apps. The same feature must not be enabled simultaneously in both the firmware and the original Router App.
Added
- Added support for selecting which Constellations to use in GNSS Configuration and improved GNSS status to display satellites from all used constellations.
- Added exFAT support. This enables the use of USB flash drives formatted in Microsoft Windows.
- Added Last Factory Reset and SSH Fingerprint to Security Information in General Status.
- Added dialog allowing users to set Syslog Minimum Severity to Debug when enabling Mobile WAN debugging.
- Added warning The current HTTPS certificate is insufficient for the selected Security Level. to remind users to Generate a new certificate.
- Added File Extension indicator to the Router Apps page.
- Added more information on the USB port:
- Added USB port count (0 or 1) to
status hw. - Added USB Port status to
status ports. - Added list of USB Devices to the system
report.
- Added USB port count (0 or 1) to
- Added
esimtool for eSIM profile management on EC25-EUX, RG255C-GL, and RM520N-GL, used in customer project deployments. - Enabled
tcpdumpalso on -S1 devices. For -S1 the command is limited to access/tmponly. Users should use the-Zargument to drop root privileges. - Added
tasksetcommand-line tool to ICR-4xxx routers for managing CPU affinity. - Added support for eMMC with erase blocks larger than 512 KiB.
Changed
- Changed Emergency Reset behavior to clear all user data (
/var/data), Router Apps (/opt), and device certificates (/etc/certs). Previously applied only to -S1 devices; now applies to all devices. - Increased the maximum number of Firewall rules from 32 to 64.
- Improved the reboot process:
- Changed
rebootcommand to properly shut down running services first. - Added
haltcommand that performs a shutdown, then turns off the PWR LED, and waits for 100 seconds so the device can be safely unplugged.
- Changed
- Upgraded to Linux kernel version 6.1.175. This brings upstream security patches and stability improvements.
- Upgraded OpenSSL to version 3.5.7 to address CVE-2026-28390, CVE-2026-31789, CVE-2026-34182, CVE-2026-34183, CVE-2026-45445, CVE-2026-45447 (high), CVE-2026-2673, CVE-2026-7383, CVE-2026-9076, CVE-2026-28387 to CVE-2026-28389, CVE-2026-31790, CVE-2026-34180, CVE-2026-34181, CVE-2026-42764, CVE-2026-42766 to CVE-2026-42770, and CVE-2026-45446 (medium).
- Upgraded OpenSSH to version 10.3 to address CVE-2026-35385 (high), CVE-2026-35386, CVE-2026-35387, and CVE-2026-35414 (medium).
- Upgraded BIND to version 9.18.49 to address CVE-2026-1519, CVE-2026-3039, CVE-2026-5946 (high), CVE-2026-3592, and CVE-2026-5950 (medium).
- Upgraded
curlto version 8.20.0 to address CVE-2026-5773 (high), CVE-2026-1965, CVE-2026-3783, CVE-2026-3784, CVE-2026-3805, CVE-2026-4873, CVE-2025-5399, CVE-2026-5545, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-7168, CVE-2025-9086, CVE-2025-10148, CVE-2025-10966, CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079 (medium), and CVE-2025-15224 (low). - Upgraded
jqto version 1.8.2 to address CVE-2026-32316 (high). - Upgraded
sudoon -S1 routers to version 1.9.17p2. - Upgraded 2nd level bootloader (AT91Bootstrap) on ICR-2xxx to version 4.0.12 and changed DDR2 settings to be JEDEC compliant.
- Switched the RM520N-GL internal communication from MBIM to QMI.
Removed
- Removed support for Huawei ME909s, previously used in SL306 EoL.
Fixed
- Improved file download throughput for all 5G ICR-4xxx routers.
- Fixed a high-severity vulnerability in the web administration interface (CVE-2026-14339). An unauthenticated remote attacker could send a POST request with an excessively large Content-Length to trigger a buffer overflow, causing a denial of service and potentially remote code execution.
- Fixed GNSS SNMP replies to return
noSuchInstanceinstead ofgenErrorwhen the location is unknown. - Fixed IPsec IKE Lifetime validation to be skipped for IKEv1 protocol. Also, the field is now disabled when IKE Reauthentication is disabled.
- Fixed error on -S1 devices after applying Automatic Update configuration without a CA certificate.
- Fixed reliability of reading the U-Boot environment. In some situations this could cause SmartFlex routers to have wrong MAC addresses.
- Fixed partial configuration restore to not have unintended impact on configuration of time synchronization.
- Fixed SMS retrieval on ICR-2437. Also improved performance when retrieving multiple SMS messages on any router.
- Fixed Network Type selection list for routers with EC25-AF, EC25-AFX, and EC25-J. Previously, GPRS was offered even though these modules do not support it.
- Fixed a few typos through the Web GUI.