# Changelog

## v6.3.12 (2024-03-27)

- Fixed crash of autoupdate
- Added custom field to SNMP
- Added build flags to /etc/os-release

## v6.3.11 (2024-02-07)

- Added automatic WiFi channel selection
- Added CPU & Memory Usage information
- Added support for SIP ALG functionality
- Added date information to generated email
- Added OID for the current profile
- Added build IDs to generated binaries
- Added external debugging symbols for proprietary FW sources
- Added option to set time from browser
- Added custom field to SNMP
- Improved check whether hostapd is running
- Increased buffer for licenses
- Removed support of UART data bits 5 and 6
- Fixed crash of totd daemon during DoS Attack
- Fixed minor issue with VRRP ping interval
- Fixed minor issue with SNMP Get for the serial number
- Fixed minor issue with docker daemon
- Fixed out of memory issue caused by libthread_db.so library
- Fixed Ntpdate buffer overflow
- Fixed U-boot compilation when libmd library is installed
- Fixed sending mobileReportPeriod value via SNMP
- Added PPP_REGISTRATION_TOUT parameter to configure the cellular registration timeout

## v6.3.10 (2023-04-28)

- Resolved GRE keepalive via sysctl instead of by kernel patch
- Upgraded program curl to version 8.0.1
- Fixed applying settings to any Ethernet configuration
- Fixed LAN interface failure when using PPPoE line
- Upgraded library OpenSSL to version 1.1.1t
- Fixed NTP service not updating RTC clock
- Stopped unnecessary update of system log on web
- Fixed tc segmentation fault
- Added other licenses info to FW info page
- Upgraded program BusyBox to version 1.36.0

## v6.3.9 (2023-01-04)

- Fixed reading information about mobile connection via SNMP
- Fixed occasional IPsec hang when terminating connection
- Improved security by running VRRP in unprivileged mode
- Upgraded library OpenSSL to version 1.1.1s
- Fixed CVE-2022-30065 in program BusyBox
- Fixed CVE-2022-44792 in program Net-SNMP
- Fixed CVE-2022-44793 in program Net-SNMP

## v6.3.8 (2022-12-02)

- Added support of WiFi interfaces to SNMP
- Added support of product revision to web interface and SNMP
- Added password validation to CGI scripts
- Improved security by running several services in unprivileged mode
- Increased timeout for sending SMS to 20 seconds
- Increased timeout for network registration for Webbing SIM cards to 5 minutes
- Disabled weak ciphers MD4 and RC4 in OpenSSL library
- Fixed occasional failure to send data to Ethernet
- Fixed minor issue with 802.1X authentication over Ethernet
- Upgraded library zlib to version 1.2.13
- Upgraded program curl to version 7.86.0
- Upgraded program dnsmasq to version 2.87
- Upgraded program dhcp-isc to version 4.1-ESV-R16-P2
- Upgraded program iptables to version 1.8.8
- Upgraded program strongSwan to version 5.9.8
- Upgraded program tcpdump to version 4.99.1

## v6.3.7 (2022-09-27)

- Added support of login banner to SSH server configuration
- Added support of login banner to HTTP server configuration
- Added support of displaying live data in the web interface
- Added package versions to the license list in the web interface
- Added support of license lists in User Modules
- Added possibility to set timeout for command "gsmat"
- Improved security by running several services in unprivileged mode
- Enabled HSTS policy mechanism in case that HTTP access is disabled
- Disabled TLS 1.0 and TLS 1.1 in default configuration
- Removed limitations of configuration parameter length
- Fixed occasional crashing of VRRP daemon
- Fixed calling  IPsec and OpenVPN up/down scripts in alternative profiles
- Fixed CVE-2022-1012 in Linux kernel
- Fixed CVE-2022-20368 in Linux kernel
- Fixed CVE-2022-32296 in Linux kernel
- Fixed CVE-2022-36946 in Linux kernel
- Fixed CVE-2022-37434 in library zlib
- Fixed CVE-2022-28391 in program BusyBox
- Replaced package inetutils with pure-ftpd
- Upgraded library OpenSSL to version 1.1.1q
- Upgraded library glibc to version 2.35
- Upgraded program Net-SNMP to version 5.9.3
- Upgraded program curl to version 7.85.0

## v6.3.6 (2022-06-16)

- Added support of asymmetric PSK to IPsec configuration
- Added match extension "u32" to iptables
- Improved DHCP server status in web interface
- Fixed VLAN/VRF ID listing in program "ip"
- Upgraded library OpenSSL to version 1.1.1o
- Upgraded program curl to version 7.83.1
- Upgraded program net-snmp to version 5.9.1
- Upgraded program strongSwan to version 5.9.6

## v6.3.5 (2022-04-20)

- Added support of TAP interface to OpenVPN configuration
- Added support of changing device ID for remote logging
- Added program "dd" for copying files
- Renamed User Modules to Router Apps
- Upgraded library zlib to version 1.2.12
- Upgraded library OpenSSL to version 1.1.1n
- Upgraded program OpenVPN to version 2.4.12

## v6.3.4 (2022-02-09)

- Added support of second remote IP address to IPsec configuration
- Added support of second remote IP address to OpenVPN configuration
- Added support of user-defined up/down scripts to IPsec configuration
- Added support of user-defined up/down scripts to OpenVPN configuration
- Added support of passphrase to OpenVPN configuration
- Added support of username and password in OpenVPN X.509 multiclient mode
- Added support of setting MTU to IPsec configuration
- Added support of setting MTU on Ethernet interfaces
- Added support of regenerating SSH key
- Added support of automatic redirect to a welcome page
- Added support of resolving "localhost"
- Added invalidation of other active sessions after password change
- Fixed IPsec malfunction when ID does not match certificate subject
- Fixed CVE-2021-20322 in Linux kernel
- Fixed CVE-2021-45486 in Linux kernel
- Upgraded library libnl to version 3.2.25
- Upgraded program hostapd to version 2.10
- Upgraded program ppp to version 2.4.9
- Upgraded program strongSwan to version 5.9.5
- Upgraded program wpa_supplicant to version 2.10

## v6.3.3 (2021-12-13)

- Added support of Cisco FlexVPN to IPsec
- Added waiting for RESET button release before resetting
- Renamed menu item "LAN" to "Ethernet" in web interface
- Enabled permanent displaying Location and Name in web interface
- Changed default TTL for GRE packets to 64
- Fixed remote access issue when using route-based IPsec
- Fixed possible reflected XSS attack
- Fixed exit code of program "snmptrap"
- Upgraded program BusyBox to version 1.34.1
- Upgraded program OpenSSH to version 8.8p1
- Upgraded program strongSwan to version 5.9.4

## v6.3.2 (2021-09-30)

- Added support of WPA3 security
- Added program "shred"
- Added program "sysctl"
- Added match extension "addrtype" to iptables
- Added information about frequency band and signal to SNMP
- Added information about RAM and CPU usage to SNMP
- Enabled SFTP file access logging
- Enabled protection against TCP TIME-WAIT Assassination
- Disabled compression and deprecated ciphers in OpenSSL library
- Improved security of Linux kernel and userspace
- Improved security of HTTP(S)
- Improved security of cookies
- Improved security and interoperability of IPsec
- Fixed setting of Perfect Forward Secrecy in IPsec
- Fixed programming of XC-CNT boards
- Upgraded library OpenSSL to version 1.1.1l
- Upgraded program curl to version 7.79.1

## v6.3.1 (2021-07-21)

- Added support of setting MTU and MRU to PPTP configuration
- Added support of setting MTU and MRU to L2TP configuration
- Increased number of firewall rules from 8 to 16
- Fixed checking IPsec SA for multiple tunnels with same IDs
- Fixed WiFi interface statistics
- Fixed CVE-2020-24586 in Linux kernel
- Fixed CVE-2020-24587 in Linux kernel
- Fixed CVE-2020-24588 in Linux kernel
- Fixed CVE-2020-26139 in Linux kernel
- Fixed CVE-2020-26147 in Linux kernel
- Upgraded program dhcp-isc to version 4.1-ESV-R16-P1
- Upgraded program curl to version 7.78.0
- Upgraded program strongSwan to version 5.9.3

## v6.3.0 (2021-05-07)

- Added support of Multi SSID
- Added support of route-based VPN to IPsec
- Added support of certificate-chain validation in IPsec
- Added support of certificate revocation check to IPsec
- Changed remote syslog to use standard RFC 3164 format
- Upgraded program OpenSSH to version 8.5p1
- Upgraded program OpenVPN to version 2.4.11
- Upgraded program dnsmasq to version 2.85
- Upgraded program strongSwan to version 5.9.2

## v6.2.9 (2021-04-07)

- Added detailed information about the signal to mobile network status
- Added programs "basename", "cut", "dirname", "printf", "readlink" and "realpath"
- Added JavaScript validation of string inputs
- Changed default APN for PLMN 22603 to "broadband"
- Changed default APN for PLMN 22610 to "net"
- Upgraded library OpenSSL to version 1.1.1k
- Upgraded program curl to version 7.76.0
- Upgraded program ftpd to version 2.0

## v6.2.8 (2021-02-19)

- Added support of tls-crypt mode to OpenVPN configuration
- Added support of setting local IP address to GRE configuration
- Added ability to restrict HTTPS to TLS 1.3
- Added program doas as a replacement for program sudo
- Enabled automatic reboot when all memory is exhausted
- Enabled authoritative mode of DHCP server for WiFi clients
- Fixed resolving of IP address in OpenVPN
- Fixed possible reflected XSS attack
- Upgraded library OpenSSL to version 1.1.1j
- Upgraded program curl to version 7.74.0
- Upgraded program dnsmasq to version 2.84

## v6.2.7 (2020-12-17)

- Added support of Short GI to WiFi AP configuration
- Added support of Hardware UUID
- Added programs "port1" and "port2" for controlling expansion ports
- Added logging of user authentication failure when accessing the web interface
- Improved permission checking when executing commands like "status"
- Enabled support of POSIX message queues in Linux kernel
- Fixed importing encrypted key from file
- Fixed CVE-2020-25705 in Linux kernel
- Upgraded library OpenSSL to version 1.1.1i
- Upgraded program OpenVPN to version 2.4.10
- Upgraded pam_tacplus plugin to version 1.6.1

## v6.2.6 (2020-09-11)

- Added description field for each FW and NAT rule
- Enabled support of VRF Lite in Linux kernel
- Enabled support of UNIX98 pseudoterminals
- Changed default APN for PLMN 24007 to "4g.tele2.se"
- Changed default APN for PLMN 45403 to "mobile.three.com.hk"
- Changed default APN for PLMN 42501 and MSIN 9320xxxxxx to "wbdata"
- Fixed rare issue when restarting SNMP service
- Upgraded program dnsmasq to version 2.82

## v6.2.5 (2020-06-13)

- Added support for 802.1X authentication via Ethernet interfaces
- Changed password encryption method from MD5 to SHA256
- Increased maximum number of parameters in a configuration file to 1000
- Disabled autocomplete of password fields
- Hidden sensitive information in web interface
- Fixed crashing of Linux kernel unaligned memory access
- Fixed detection of MRAM during startup
- Upgraded program strongSwan to version 5.8.4

## v6.2.4 (2020-04-25)

- Added support of SHA384 to IPsec
- Added configuration of restraints for FTP and Telnet
- Added configuration of minimum TLS protocol version
- Added information about misaligned memory access to the report file
- Changed default APN for PLMN 45435 to "wbdata"
- Fixed crashing of Linux kernel during WiFi communication
- Fixed unlocking and unblocking SIM card
- Fixed information about flags of bridges interfaces
- Fixed CVE-2019-5108 in Linux kernel
- Fixed CVE-2019-18282 in Linux kernel
- Fixed CVE-2020-8597 in program pppd
- Fixed CVE-2018-5388 in program strongSwan
- Fixed CVE-2018-10811 in program strongSwan
- Upgraded program OpenVPN to version 2.4.9
- Upgraded program dhcpcd to version 7.2.5
- Upgraded program dnsmasq to version 2.81
- Upgraded program ftpd to version 1.9.4
- Upgraded program sudo to version 1.8.31

## v6.2.3 (2020-02-11)

- Added checking of DPD delay and DPD timeout in IPsec configuration
- Reworked restarting WiFi so AP and STA are started independently
- Disabled reverse IP lookup in PAM RADIUS plugin
- Disabled reverse IP lookup in FTP server
- Fixed several bugs in VRRP
- Fixed restoring default configuration when RST button is pressed during boot sequence
- Fixed manual assignment of DNS servers for mobile connection
- Fixed processing of very long AT command response
- Fixed initial setup of Cinterion PHS8 modules

## v6.2.2 (2019-12-16)

- Added programs "snmpget" and "snmpset"
- Added support of PAM TACACS+ authentication
- Added taking over of server users during RADIUS/TACACS+ authentication
- Changed format of transferred data in output of "status -v" command
- Increased maximum number of pending TCP connections in HTTP server
- Fixed detection of link status in Ethernet driver
- Fixed memory access failure when executing programs
- Fixed routing packets over IPsec with overlapping subnets
- Fixed establishing of L2TP tunnel
- Fixed CVE-2019-16275 in program hostapd
- Upgraded program curl to version 7.67.0

## v6.2.1 (2019-10-16)

- Added support of inotify for monitoring filesystem events
- Added support of 64-bit traffic counters
- Fixed counting transferred data over mobile connection
- Fixed processing of non-standard responses to AT commands
- Fixed memory access failure when executing programs
- Fixed access to FTP/PPTP server behind NAT
- Fixed crashing of PPTP client
- Fixed setting of Ethernet PHY
- Fixed RS485 direction control for short transfers
- Fixed CVE-2019-16746 in Linux kernel
- Fixed CVE-2019-17133 in Linux kernel
- Upgraded library OpenSSL to version 1.0.2t
- Upgraded library libpcap to version 1.9.1
- Upgraded program tcpdump to version 4.9.3

## v6.2.0 (2019-08-16)

- Added support of load balancing
- Added support of interface selection to PPPoE client
- Added support of IEEE 802.1Q to PPPoE client
- Added support of PAM RADIUS authentication
- Added support of hardware flow control
- Added support of loading certificates in PEM format
- Added support of loading certificates in PKCS#12 format
- Added support of VRRPv3 and the second instance
- Changed look of the web interface
- Applied toolchain hardening
- Disabled insecure services in default configuration
- Fixed netmask validation
- Upgraded Linux kernel to version 4.14.138
- Upgraded library glibc to version 2.30
- Upgraded program OpenVPN to version 2.4.7
- Upgraded program curl to version 7.65.3
- Upgraded program sudo to version 1.8.22
- Upgraded program iptables to version 1.4.21
- Upgraded program iproute2 to version 4.14.1
- Upgraded program iw to version 4.14
- Upgraded program hostapd to version 2.9
- Upgraded program wpa_supplicant to version 2.9

## v6.1.10 (2019-07-02)

- Added protection against brute force attacks
- Added filtering out of sensitive data from the report
- Added support of backup and restore of encrypted configuration
- Added support of dynamic starting time of automatic update
- Added dropping SYN packets with suspicious MSS value
- Extended compatibility check of uploaded user modules
- Enabled OpenVPN management interface
- Fixed route selection in Multi WAN mode
- Fixed getting mobile network registration status
- Fixed CVE-2019-11477 in Linux kernel
- Fixed CVE-2019-11478 in Linux kernel

## v6.1.9 (2019-04-23)

- Added program "nohup"
- Added program "report"
- Added program "umupdate"
- Added possibility to set timeout for checking connection
- Added possibility to set port range to Firewall and NAT configuration
- Added information about additional interfaces into SNMP
- Modified comparison of firmware versions
- Modified switching to another SIM card after modem hangup
- Modified reading out ICCID from SIM card
- Fixed JavaScript on page SMTP Configuration
- Fixed JavaScript on page SMS Configuration
- Fixed kernel crash after change of bridge configuration
- Upgraded library OpenSSL to version 1.0.2r
- Upgraded program OpenSSH to version 8.0p1
- Upgraded program curl to version 7.64.1
- Upgraded program dnsmasq to version 2.80
- Upgraded program hostapd to version 2.8
- Upgraded program wpa_supplicant to version 2.8

## v6.1.8 (2018-11-08)

- Added command "sync"
- Added logging of user actions
- Added configuration of syslog service
- Added support of uploading HTTPS certificate
- Added support of mirroring network traffic
- Added information about product type into program "status"
- Added information about expected range of values to web interface
- Changed default APN for PLMN 24202 to "internet.telia.no"
- Fixed selection of PSK for IKEv1 Main Mode
- Fixed update of DynDNS record
- Fixed crashing of DHCP client
- Fixed LED SIM state after firmware start
- Fixed CVE-2018-14526 in program wpa_supplicant
- Upgraded library OpenSSL to version 1.0.2p
- Upgraded program BusyBox to version 1.29.3
- Upgraded program Net-SNMP to version 5.8
- Upgraded program OpenSSH to version 7.9p1
- Upgraded program curl to version 7.62.0

## v6.1.7 (2018-07-25)

- Added digital signature of firmware
- Added match extension "policy" to iptables
- Added new options to program "led"
- Added support of DNS configuration to PPPoE
- Removed support of dial-in mode
- Modified authorization of SMS command "REBOOT"
- Modified texts of informational SMS
- Modified SIM cards statistics and connection log
- Modified threshold of good and bad signal level
- Modified validation of netmask
- Modified selection of local IP address for IPsec tunnels
- Fixed counting of transferred data
- Fixed selection of SNMP trap agent-addr
- Fixed overwriting of parameter PORT_MODE during import of partial configuration
- Upgraded library OpenSSL to version 1.0.2o
- Upgraded program curl to version 7.61.0

## v6.1.6 (2018-03-11)

- Added support of GCM ciphers to IPsec
- Added support of ECP DH groups to IPsec
- Added support of XAUTH to IPsec
- Added support of PubKey to IPsec
- Added support of IKEv2 reauthentication IPsec
- Added program "split"
- Added list of opened TCP and UDP sockets to the report file
- Added information from installed user modules to the report file
- Allowed using special characters in password for new user account
- Changed default APN for PLMN 23201 to "a1.net"
- Increased watchdog timeout
- Improved emergency reboot in case of unrecoverable kernel failure
- Improved throughput of the second Ethernet
- Fixed multiple issues in the second Ethernet driver
- Fixed multiple issues in FLASH driver
- Fixed MAC address in SNMP in case of active VRRP
- Fixed static routes via PPPoE and bridged interfaces
- Fixed CVE-2017-18017 in Linux kernel
- Upgraded program curl to version 7.58.0
- Upgraded program dhcp-isc to version 4.1-ESV-R15-P1

## v6.1.5 (2017-12-19)

- Added protocols GRE and ESP to firewall configuration
- Added emergency reboot in case of unrecoverable kernel failure
- Improved compatibility of IKEv2 protocol
- Hidden sensitive information in web interface
- Fixed WPA2 vulnerabilities
- Fixed detection of USB device speed
- Fixed calculation of connection uptime
- Fixed RS485 initialization after power up
- Fixed memory leaks in processing fragmented packets
- Fixed multiple issues in the second Ethernet driver
- Upgraded firmware in WiFi module to version 0.36
- Upgraded library OpenSSL to version 1.0.2n
- Upgraded program OpenSSH to version 7.6p1
- Upgraded program curl to version 7.57.0
- Upgraded program dnsmasq to version 2.78
- Upgraded program hostapd to version 2.6
- Upgraded program wpa_supplicant to version 2.6

## v6.1.4 (2017-09-27)

- Added timestamps to the kernel log
- Added list of installed user modules to report file
- Added program "top"
- Enabled resizing of "vi" editor window
- Fixed IPsec tunnel termination
- Fixed IPsec tunnel checking mechanism
- Fixed removing iptables rules after IPsec termination
- Fixed routing of the second subnet over IPsec tunnel
- Fixed restarting of SSH server
- Fixed crash of EHCI driver
- Fixed calculation of connection uptime
- Fixed switching between dial-in and dial-out mode
- Upgraded program OpenVPN to version 2.3.18
- Upgraded program tcpdump to version 4.9.2

## v6.1.3 (2017-08-10)

- Added protection against Clickjacking and XSS attacks
- Added wait for firmware update finish to program "reboot"
- Added match extension "statistic" to iptables
- Disabled renegotiation of SSL connection
- Fixed registration to unavailable mobile network
- Fixed reset of mobile statistics at time shift
- Fixed occasional freezing of backup routing daemon
- Fixed multiple issues in WiFi driver
- Fixed setting TX power on WiFi
- Fixed GRE tunnel initialization
- Fixed IPsec tunnel termination
- Upgraded program OpenVPN to version 2.3.17
- Upgraded program tcpdump to version 4.9.1

## v6.1.2 (2017-06-12)

- Added support of generic CDC-ECM devices
- Added automatic hiding of absent Ethernet interfaces
- Added target "TCPMSS" and match extension "tcpmss" to iptables
- Added programs "cmp", "head" and "wc"
- Added filtering of uploaded files by extension
- Added compatibility check of uploaded user modules
- Added safer cellular module shutdown
- Changed default APN for PLMN 26201 to "internet.telekom"
- Changed IKEv1 payload order due to better interoperability
- Removed mechanism that causes reboots in case of no mobile connectivity
- Fixed occasional freezing of communication over WiFi
- Fixed switching back to default SIM card
- Fixed sending warning SMS after exceeding the data limit
- Fixed terminating of L2TP tunnel
- Fixed terminating of program "nc"
- Fixed CVE-2016-10229 in Linux kernel
- Downgraded program iproute2 to version 3.5.0
- Upgraded program OpenVPN to version 2.3.15
- Upgraded program strongSwan to version 5.5.3
- Upgraded program iw to version 3.5
- Upgraded library zlib to version 1.2.11

## v6.1.1 (2017-03-09)

- Added support of static routes
- Added support of backing up and restoring of user accounts
- Added support of L2TP in Linux kernel
- Added match extension "string" to iptables
- Improved security of cookies that are sent over HTTPS connection
- Modified storing content of text areas
- Modified selection of preferred operator
- Fixed automatic update of firmware
- Fixed setting of IDs in IPsec when distinguished name is used
- Fixed redirecting services to non-defaults ports
- Fixed buffer overflow in program "status"
- Fixed CVE-2017-5970 in Linux kernel
- Fixed CVE-2017-6214 in Linux kernel
- Upgraded program tcpdump to version 4.9.0
- Upgraded program OpenSSH to version 7.4p1
- Upgraded library OpenSSL to version 1.0.2k
- Upgraded library glibc to version 2.25

## v6.1.0 (2016-12-15)

- Added support of IKEv2 for IPSec VPN
- Added support of authentication on Ethernet
- Added support of forcing NAT Traversal
- Added support of EAP-TLS authentication on WiFi
- Added support of SCP protocol
- Added support of HTTP server configuration
- Added support of SSH server configuration
- Added support of unblocking SIM card
- Added program "stty"
- Added target "NFQUEUE" to iptables
- Fixed memory exhaustion in SSH server
- Fixed termination of SSL connection in HTTP server

## v6.0.3 (2016-12-08)

- Upgraded program curl to version 7.51.0
- Upgraded program dnsmasq to version 2.76

## v6.0.2 (2016-10-21)

- Added license information
- Added showing error message for unsupported WiFi channels
- Fixed selecting bridged interface with dynamic IP address as backup route
- Fixed priorities for selecting backup route
- Fixed CVE-2016-7117 in Linux kernel
- Upgraded program conntrack-tools to version 1.0.1
- Upgraded library libnetfilter_conntrack to version 1.0.1
- Upgraded library libnfnetlink  to version 1.0.1
- Upgraded library glibc to version 2.24
- Upgraded library OpenSSL to version 1.0.2j

## v6.0.1 (2016-09-07)

- Added filtering out all forwarded invalid RST and FIN packets
- Reworked firmware update progress indicator
- Increased maximum value of Data Limit to 2 TB
- Increased size of ICMP packets for checking connection
- Changed default APN for PLMN 23820 to "internet.ts.m2m"
- Changed default APN for PLMN 24202 to "tsn"
- Fixed turning on SIM LED after router power up
- Fixed switching SIM card via SMS
- Fixed conversion of Mobile WAN configuration
- Fixed handling premature disconnection of HTTP client
- Fixed reading statistics via SNMP protocol
- Upgraded program OpenSSH to version 7.3p1
- Upgraded program curl to version 7.50.1

## v6.0.0 (2016-06-29)

- Added support of client isolation on WiFi
- Added support of client authentication on WiFi
- Added support of controlling RS485 from Linux kernel
- Added support of Multiple WAN
- Removed support of "Extra Options" from IPsec configuration
- Removed program setkey
- Reworked configuration of switching SIM cards
- Reworked configuration and starting VPN tunnels
- Upgraded program iproute to version 3.12.0

## v5.3.6 (2016-05-31)

- Updated WiFi regulatory database
- Removed support of WiFi channel 14
- Fixed processing of long response from DynDNS server
- Fixed setting community for 2nd SNMP user after firmware upgrade
- Upgraded program OpenVPN to version 2.3.11
- Upgraded library OpenSSL to version 1.0.2h

## v5.3.5 (2016-05-03)

- Optimized firmware update
- Changed parameters for generating HTTPS certificates (V3, SHA2, RSA-2048)
- Disabled weak cipher RC4 in HTTPS server
- Fixed potential vulnerability in HTTP(S) server
- Fixed login to router from R-WebDog system
- Fixed decoding phone number in alphanumeric format
- Fixed reading 20-digit ICCID from SIM card
- Fixed initialization of 4th IPsec tunnel
- Fixed CVE-2014-8160 in Linux kernel
- Fixed CVE-2014-8709 in Linux kernel
- Fixed CVE-2015-5364 in Linux kernel
- Fixed CVE-2015-5366 in Linux kernel
- Fixed CVE-2016-0821 in Linux kernel
- Upgraded program dhcp-isc to version 4.1-ESV-R13
- Upgraded program OpenSSH to version 7.2p2
- Upgraded library OpenSSL to version 1.0.1t

## v5.3.4 (2016-03-10)

- Modified firmware name check before update
- Fixed redirect after login
- Fixed unpacking tar archives with long filenames
- Upgraded library glibc to version 2.23
- Upgraded library OpenSSL to version 1.0.1s

## v5.3.3 (2016-02-12)

- Changed mode for receiving and sending SMS to PDU
- Fixed JFFS2 corruption after read or write failure
- Fixed processing of IPSec packets when subnets are overlapping each other
- Upgraded program dhcp-isc to version 4.1-ESV-R12-P1
- Upgraded program OpenSSH to version 7.1p2
- Upgraded library OpenSSL to version 1.0.1r

## v5.3.2 (2015-12-10)

- Added target "CONNMARK" and match extension "connmark" to iptables
- Fixed regression in command "mount"
- Fixed missing CSRF token check
- Fixed redirect back to "LAN Configuration" page after applying changes
- Fixed reading SMS that contains "greater than" sign via AT-SMS protocol

## v5.3.1 (2015-10-26)

- Changed absolute URLs to relative in HTTP redirects
- Fixed order of selectable backup routes in backward compatible mode
- Fixed restoring configuration from partial backup

## v5.3.0 (2015-10-13)

- Added support of 4 OpenVPN tunnels
- Added support of DHCP server on all LAN ports
- Added support of bridge in backup routes
- Added support of multiuser access
- Added CSRF attack protection
- Added passing variables SERVER_ADDR  and SCRIPT_NAME to executed CGI scripts
- Enabled support of high resolution timers in the kernel
- Updated list of USB/RS-232 converters with chip CP210x
- Changed ARP behaviour (arp_ignore=1, arp_announce=2)
- Changed default APN for PLMN 23420 to "3ireland.ie"
- Changed default APN for PLMN 27202 to "internet"
- Modified router login page
- Modified firmware update page
- Fixed switching backup routers between mobile connection and PPPoE
- Fixed regression in command "killall"
- Fixed starting IPsec tunnels under heavy load
- Upgraded program OpenSSH to version 7.1p1
- Upgraded program OpenVPN to version 2.3.8
- Upgraded program Openswan to version 2.6.43.1
- Upgraded program Net-SNMP to version 5.7.3

## v5.2.1 (2015-07-17)

- Prohibited processing DNS TCP request from WAN
- Fixed rebinding DHCP lease after carrier loss
- Fixed getting IP addresses of DNS servers
- Fixed termination of OpenVPN tunnel
- Fixed stopping VRRP daemon when multiple instances are running
- Downgraded program dhcpcd to version 6.4.7
- Upgraded program dnsmasq to version 2.73
- Upgraded program hostapd to version 2.4
- Upgraded program wpa_supplicant to version 2.4
- Upgraded library OpenSSL to version 1.0.1p

## v5.2.0 (2015-06-09)

- Added support of second SNMP user
- Added support of caching static files
- Added target "DSCP" and match extension "dscp" to iptables
- Disabled weak ciphers CBC and RC4 in SSH server
- Disabled weak ciphers CBC, RC4, SEED, CAMELLIA and IDEA in HTTPS server
- Fixed CVE-2013-4345 in Linux kernel
- Fixed CVE-2013-4348 in Linux kernel
- Fixed CVE-2013-7027 in Linux kernel
- Fixed CVE-2014-2706 in Linux kernel
- Fixed CVE-2015-3294 in program dnsmasq
- Fixed potential vulnerability in parsing malformed HTTP request
- Fixed regression in command "ip addr show" that stopped showing IP addresses
- Fixed separation of HTTP headers to comply with RFC 2616
- Fixed filtering of VRRP packets in firewall
- Fixed checking of type of recevied VRRP packets
- Fixed sending of gratuitous ARP packets at state transitions
- Upgraded program BusyBox to version 1.23.2
- Upgraded program OpenSSH to version 6.8p1
- Upgraded program OpenVPN to version 2.3.6
- Upgraded program curl to version 7.42.1
- Upgraded program dhcp-isc to version 4.1-ESV-R11
- Upgraded program dhcpcd to version 6.8.2
- Upgraded program ppp to version 2.4.7
- Upgraded program tcpdump to version 4.7.4
- Upgraded library gmp to version 6.0.0a
- Upgraded library lzo to version 2.09
- Upgraded library pcap to version 1.7.3
- Upgraded library zlib to version 1.2.8
- Replaced program arp with BusyBox applet
- Replaced program brctl with BusyBox applet
- Replaced program vconfig with BusyBox applet

## v5.1.3 (2015-04-24)

- Downgraded OpenSSL to version 1.0.1m

## v5.1.2 (2015-04-09)

- Upgraded OpenSSL to version 1.0.2a

## v5.1.1 (2015-04-01)

- Fixed loading WiFi configuration from alternative profiles

## v5.1.0 (2015-03-16)

- Added support of reading ICCID via SNMP protocol
- Added support of reading CSQ via SNMP protocol
- Added support of SHA256 and SHA512 in IPsec tunnels
- Added support of IPsec BEET mode into kernel
- Added parameter "Protocol/Port" to IPsec tunnel configuration
- Added parameter "Inactivity Timeout" to expansion port configuration
- Added selective flush of conntrack table after switching backup route
- Added locking mechanism to avoid multiple start of firmware update
- Added mechanism to recover from deleting configuration
- Added library libstdc++.so
- Fixed 5-bits and 6-bits mode on serial line
- Upgraded OpenSSL to version 1.0.2
- Upgraded glibc to version 2.21
- Upgrade iproute2 to version 3.5.0

## v5.0.0 (2014-12-02)

- Added support of SMTPS
- Added support of chaning SMTP port
- Added support of downloading firmware and configuration from HTTPS/FTPS server
- Added SSH klient
- Added SFTP server
- Added program "curl"
- Added program "find"
- Added program "fwupdate"
- Added program "ip rule"
- Added program "nc"
- Added program "netstat"
- Added program "pidof"
- Added program "xargs"
- Added information about product type into report
- Added automatic closing of SSH connection after 10 minutes of inactivity
- Reduced number of concurrent unauthenticated SSH connections and authentication attempts
- Disabled SSLv3 support in HTTPS protocol
- Enabled change of WEP default key index for WiFi STA mode
- Fixed function of XC-ETH in second expansion slot for setting 10 Mbps half duplex
- Fixed getting of MAC address of interface eth0 if VRRP is enabled
- Fixed manual restarting of pppsd service
- Upgraded WPA Supplicant to version 2.0

## v4.0.1 (2014-08-21)

- Added support of DirectIP connection for Sierra Wireless MC8705 modules
- Added support of PPPoE
- Added support of connecting to WiFi network with hidden SSID
- Added blocking of incoming traffic on all non-selected backup routes
- Added library libm.so
- Added filesystem devtmpfs
- Reduced SSH login timeout to 1 minute
- Removed unnecessary erasing of FLASH during firmware update
- Fixed function of XC-ETH in second expansion slot
- Fixed initialization of timer for MACB controller
- Fixed receiving data from serial line
- Fixed reading of SMS when SIM card is full
- Fixed reading of operator name
- Fixed return to automatic network type selection
- Fixed NAT traversal support that was mistakenly removed from Openswan
- Fixed invalid value of SNMP OID mobileDisconnect
- Upgraded ppp to version 2.4.6

## v4.0.0 (2014-04-15)

- Added support of WiFi
- Added support of multicast on GRE tunnels
- Added support of switching back to primary SIM card after timeout even if roaming was detected
- Added password check when remote access is enabled
- Added indication of expansion board XC-SD
- Added passing of interface name to scripts ip-up and ip-down in user modules
- Added default APN "com4" for PLMN 24209
- Enhanced configuration of firewall
- Modified reading of temperature and supply voltage via SNMP protocol
- Modified default APN for PLMN 23205 to "fullspeed"
- Modified displaying of timestamps on page DHCP Status
- Modified value of enterprise OID in SNMP traps
- Enabled SMS reading from module when connection is not established or not in offline mode
- Disabled remote access via SNMP in default configuration
- Prohibited processing DNS request incoming from WAN
- Removed router identification during login process
- Removed automatic reboot due to non-registering to mobile network
- Fixed identification of backup route parameter change
- Fixed online to offline mode change when same SIM card is used
- Fixed VRRP initialization
- Fixed processing of IPSec packets when subnets are overlapping each other
- Fixed reading of signal strength from HC25, EU3 and PHS8 modules
- Fixed reading SMS from PHS8 module
- Upgraded kernel to version 3.5.0
- Upgraded OpenSSL to version 1.0.1g
- Upgraded OpenSSH to version 6.4p1
- Upgraded OpenVPN to version 2.3.3
- Upgraded OpenSWAN to version 2.6.41
- Upgraded dhcpcd to version 6.2.1
- Upgraded dnsmasq to version 2.68
- Upgraded ftpd to version 1.9.2
- Upgraded ppp to version 2.4.5
- Upgraded pptp to version 1.8.0
- Upgraded pptpd to version 1.4.0
- Upgraded tcpdump to version 4.5.1

## v3.0.9 (2013-11-20)

- Added program "getty"
- Added support of overriding values from DHCP by settings from configuration
- Added support of PPTP passthrough
- Added temperature and supply voltage to SNMP traps
- Added displaying of network interface flags
- Added passing variables REMOTE_ADDR, REMOTE_USER and HTTP_COOKIE to executed CGI scripts
- Extended timeout for detecting SIM card status
- Extended timeout for setting preffered operator
- Extended timeout for setting preffered SMS service
- Removed deleting of all iptables rules after configuration change
- Removed logging of some unimportant warning of program l2tpd
- Fixed bug with long period for connection check after reboot
- Fixed starting of IPsec and OpenVPN tunnels after backup route change

## v3.0.8 (2013-08-30)

- Added individual configuration of ping and DNS server for each SIM card
- Added match extension "pkttype" to iptables
- Added passive check of TCP keepalive expiration
- Added delay before reopening serial line after failure
- Modified selecting of preffered operator and network type
- Modified indication of installed XC-SW expansion board
- Fixed indication of mobile network connection uptime
- Fixed decoding of invalid BCD values read out by MBUS protocol

## v3.0.7 (2013-07-12)

- Added support of USB/RS-232 converters FTDI FT232RL, FT232H, FT2232H a FT4232H
- Added support of SNMPv3
- Added support of reading registration status, operator, LAC, signal quality and MEID via SNMP protocol
- Added support of switching between different WAN interfaces
- Added support of choosing IPsec tunnels encryption
- Added support of manual setting of date and time
- Added support of configurable timeouts for each CGI script
- Added new home page
- Added button for creating detailed report
- Added logging of reboot reasons
- Added information about embedded mobile module
- Added more information about mobile network connection
- Added test of functionality of mobile module after its power up
- Added test of RST button before executing system services
- Added target "REJECT" and match extensions "mac" and "quota" to iptables
- Enabled loopback interface
- Enabled automatic correction of misaligned memory access
- Modified detection of signal strength in Sierra Wireless modules
- Modified setting of daylight saving time for USA and Australia
- Modified rejection of TCP connection if checking of TCP connection is enabled
- Modified setting of UDP packet destination port if target IP address is not specified
- Decreaced values of root delay and root dispersion in NTP server
- Increased limits for configuration files (200 lines, 8000 characters per line)
- Disabled reverse DNS lookup in SSH server
- Removed delay before the first control ping
- Fixed crashing of EHCI driver
- Fixed communication problems on second Ethernet
- Fixed communication problems with PHS8 module with GPS
- Fixed processing of multiline response from SMTP server
- Fixed updating of neighbour table
- Fixed receiving of SMS which contains text instead of phone number

## v3.0.6 (2012-10-16)

- Added support of transport mode in IPsec configuration
- Added support of HTTP proxy to OpenVPN
- Added support of reading state of binary outputs and setting state of counters to program "io"
- Added support of executing scripts "install" and "uninstall" in user modules
- Added indication of running firmware update via fast flashing of PWR LED
- Added clearing input buffer after accepting new TCP connection in AT-SMS protocol
- Added option "-I" to program ping for selecting outgoing interface
- Added option "-R" to program snmptrap for sending MAC address of interface eth0
- Added program logger
- Changed default APN for PLMN 26201 to "internet.t-mobile"
- Changed texts of automatically generated SMS
- Changed authentification sequence during logging into SMTP server
- Changed processing of packets coming from IPsec tunnel so that they aren't interfered with setting of NAT
- Removed check of minimal hostname length in DynDNS configuration
- Disabled remote access via HTTP, HTTPS, Telnet, SSH and FTP in default configuration
- Prohibited processing DNS request incoming from mobile network
- Decreased working frequency of SMI bus to 40 MHz
- Fixed default setting of shell variable PATH

## v3.0.5 (2012-06-05)

- Added support of configuring network bridge
- Added support of setting primary SIM card as backup
- Added support of setting blank APN using keyword "blank"
- Added support of USB/RS-232 converter FTDI FT230X
- Added support of reading SN, IMEI, ESN, selected SIM card and assigned IP address via SNMP protocol
- Added support of sending messages to supervisory system via SNMP protocol
- Added support of PIM-SM protocol to Linux kernel
- Added support of commands AT+CMGW, AT+CMSS and AT+COPS? into AT-SMS protocol
- Added processing of LCP Echo Request packets in PPPoE Bridge mode
- Added confirmation dialog when trying to delete module
- Added checking of secondary Ethernet interface IP address
- Added program ftpput
- Added match extension "multiport" to iptables
- Fixed filling timestamp in NTP server reply
- Fixed detection of channel, cell and signal strength in Sierra Wireless modules
- Fixed buffer size in AT-SMS protocol due to sending SMS in PDU format
- Fixed sending SMS containing LF characters
- Fixed automatic updates of DNS proxy after changing DNS servers
- Fixed stopping DHCP client after disconnecting network cable
- Fixed restoring Up/Down scripts in alternative profiles after firmware update

## v3.0.4 (2012-02-06)

- Added support of VLAN (802.1Q)
- Added support of sending SMS messages with time stamp
- Added support of reading temperature and supply voltage via SNMP protocol
- Added support of loading kernel modules and programs insmod and rmmod
- Added checking of filename when upgrading firmware via web interface
- Added checking of downloaded files during automatic firmware update
- Changed length of RSA key for SSH to 1024 bits
- Limited detecting of roaming when establishing PPP connection
- Fixed symlinks when installing user modules
- Fixed sending of long packets on eth1 interface at speed 10 Mbit/s

## v3.0.3 (2011-12-14)

- Added support of QoS
- Added support of PPTP
- Added support of GRE keepalive
- Added signal strength indication via LED PPP
- Added resending SMS after error
- Shortened time to repeat DynDNS record update after server closes connection prematurely
- Fixed termination of OpenVPN after receiving message AUTH_FAILED
- Fixed handling of IPsec packets if Remote IP Address falls within Remote Subnet

## v3.0.2 (2011-11-11)

- Upgraded driver for Sierra Wireless modules to version 1.7.40 to improve transmission speed
- Upgraded Openswan to version 2.6.37
- Upgraded dnsmasq to version 2.59
- Added program for sending SNMP traps
- Added support of using program "restore" to restore configuration from file
- Added support of USB/RS-232 converter CP210x
- Added support of command AT+CSCS into AT-SMS protocol
- Modified interval of time synchronization with NTP server from 24 hours to 8 hours

## v3.0.1 (2011-09-26)

- Added SSH server
- Added HTTPS server
- Added programs awk, grep, sed, conntrack and traceroute
- Added support of Marvell 88E6060 switch
- Added possibility to use DTR and CD signals of expansion ports for control and signaling state of TCP connection
- Added showing date and time when listing directory contents via program ls
- Replaced shell msh by ash with support for better scripting
- Adjusted generating SPI for IPsec for quicker recovery after reboot
- Fixed router identification in SNMP
- Fixed receiving of multicast frames
- Fixed crashing of VRRP daemon
- Removed password length restrictions

## v3.0.0 (2011-07-27)

- Added support of second expansion port
- Added support of Macronix 25L12835E FLASH memory
- Added support of option "defaults" to initialization scripts of user modules
- Added displaying location and name of router on web interface (from SNMP configuration)
- Added highlighting of menu item "Change Password" when router is using default password
- Fixed processing of UDP packets coming from IPsec tunnel to IP address of interface eth0
- Fixed detection of HSPA+
