# Changelog

## v6.3.12 (2024-03-27)

- Fixed crash of autoupdate
- Added custom field to SNMP
- Added build flags to /etc/os-release

## v6.3.11 (2024-02-07)

- Added automatic WiFi channel selection
- Added CPU & Memory Usage information
- Added support for SIP ALG functionality
- Added date information to generated email
- Added OID for the current profile
- Added build IDs to generated binaries
- Added external debugging symbols for proprietary FW sources
- Added option to set time from browser
- Added custom field to SNMP
- Improved check whether hostapd is running
- Increased buffer for licenses
- Removed support of UART data bits 5 and 6
- Fixed crash of totd daemon during DoS Attack
- Fixed minor issue with VRRP ping interval
- Fixed minor issue with SNMP Get for the serial number
- Fixed minor issue with docker daemon
- Fixed out of memory issue caused by libthread_db.so library
- Fixed Ntpdate buffer overflow
- Fixed U-boot compilation when libmd library is installed
- Fixed sending mobileReportPeriod value via SNMP
- Added PPP_REGISTRATION_TOUT parameter to configure the cellular registration timeout

## v6.3.10 (2023-04-28)

- Resolved GRE keepalive via sysctl instead of by kernel patch
- Upgraded program curl to version 8.0.1
- Fixed applying settings to any Ethernet configuration
- Fixed LAN interface failure when using PPPoE line
- Upgraded library OpenSSL to version 1.1.1t
- Fixed NTP service not updating RTC clock
- Stopped unnecessary update of system log on web
- Fixed tc segmentation fault
- Added other licenses info to FW info page
- Upgraded program BusyBox to version 1.36.0

## v6.3.9 (2023-01-04)

- Fixed reading information about mobile connection via SNMP
- Fixed occasional IPsec hang when terminating connection
- Improved security by running VRRP in unprivileged mode
- Upgraded library OpenSSL to version 1.1.1s
- Fixed CVE-2022-30065 in program BusyBox
- Fixed CVE-2022-44792 in program Net-SNMP
- Fixed CVE-2022-44793 in program Net-SNMP

## v6.3.8 (2022-12-02)

- Added support of WiFi interfaces to SNMP
- Added support of product revision to web interface and SNMP
- Added password validation to CGI scripts
- Improved security by running several services in unprivileged mode
- Disabled weak ciphers MD4 and RC4 in OpenSSL library
- Fixed occasional failure to send data to Ethernet
- Fixed minor issue with 802.1X authentication over Ethernet
- Upgraded library zlib to version 1.2.13
- Upgraded program curl to version 7.86.0
- Upgraded program dnsmasq to version 2.87
- Upgraded program dhcp-isc to version 4.1-ESV-R16-P2
- Upgraded program iptables to version 1.8.8
- Upgraded program strongSwan to version 5.9.8
- Upgraded program tcpdump to version 4.99.1

## v6.3.7 (2022-09-27)

- Added support of login banner to SSH server configuration
- Added support of login banner to HTTP server configuration
- Added support of displaying live data in the web interface
- Added package versions to the license list in the web interface
- Added support of license lists in User Modules
- Improved security by running several services in unprivileged mode
- Enabled HSTS policy mechanism in case that HTTP access is disabled
- Disabled TLS 1.0 and TLS 1.1 in default configuration
- Removed limitations of configuration parameter length
- Fixed occasional crashing of VRRP daemon
- Fixed calling  IPsec and OpenVPN up/down scripts in alternative profiles
- Fixed CVE-2022-1012 in Linux kernel
- Fixed CVE-2022-20368 in Linux kernel
- Fixed CVE-2022-32296 in Linux kernel
- Fixed CVE-2022-36946 in Linux kernel
- Fixed CVE-2022-37434 in library zlib
- Fixed CVE-2022-28391 in program BusyBox
- Replaced package inetutils with pure-ftpd
- Upgraded library OpenSSL to version 1.1.1q
- Upgraded library glibc to version 2.35
- Upgraded program Net-SNMP to version 5.9.3
- Upgraded program curl to version 7.85.0

## v6.3.6 (2022-06-16)

- Added support of asymmetric PSK to IPsec configuration
- Added match extension "u32" to iptables
- Improved DHCP server status in web interface
- Fixed VLAN/VRF ID listing in program "ip"
- Upgraded library OpenSSL to version 1.1.1o
- Upgraded program curl to version 7.83.1
- Upgraded program net-snmp to version 5.9.1
- Upgraded program strongSwan to version 5.9.6

## v6.3.5 (2022-04-20)

- Added support of TAP interface to OpenVPN configuration
- Added support of changing device ID for remote logging
- Added program "dd" for copying files
- Renamed User Modules to Router Apps
- Upgraded library zlib to version 1.2.12
- Upgraded library OpenSSL to version 1.1.1n
- Upgraded program OpenVPN to version 2.4.12

## v6.3.4 (2022-02-09)

- Added support of second remote IP address to IPsec configuration
- Added support of second remote IP address to OpenVPN configuration
- Added support of user-defined up/down scripts to IPsec configuration
- Added support of user-defined up/down scripts to OpenVPN configuration
- Added support of passphrase to OpenVPN configuration
- Added support of username and password in OpenVPN X.509 multiclient mode
- Added support of setting MTU to IPsec configuration
- Added support of setting MTU on Ethernet interfaces
- Added support of regenerating SSH key
- Added support of automatic redirect to a welcome page
- Added support of resolving "localhost"
- Added invalidation of other active sessions after password change
- Fixed IPsec malfunction when ID does not match certificate subject
- Fixed CVE-2021-20322 in Linux kernel
- Fixed CVE-2021-45486 in Linux kernel
- Upgraded library libnl to version 3.2.25
- Upgraded program hostapd to version 2.10
- Upgraded program ppp to version 2.4.9
- Upgraded program strongSwan to version 5.9.5
- Upgraded program wpa_supplicant to version 2.10

## v6.3.3 (2021-12-13)

- Added support of Cisco FlexVPN to IPsec
- Added waiting for RESET button release before resetting
- Renamed menu item "LAN" to "Ethernet" in web interface
- Enabled permanent displaying Location and Name in web interface
- Changed default TTL for GRE packets to 64
- Fixed remote access issue when using route-based IPsec
- Fixed possible reflected XSS attack
- Fixed exit code of program "snmptrap"
- Upgraded program BusyBox to version 1.34.1
- Upgraded program OpenSSH to version 8.8p1
- Upgraded program strongSwan to version 5.9.4

## v6.3.2 (2021-09-30)

- Added support of WPA3 security
- Added program "shred"
- Added program "sysctl"
- Added match extension "addrtype" to iptables
- Added information about RAM and CPU usage to SNMP
- Enabled SFTP file access logging
- Enabled protection against TCP TIME-WAIT Assassination
- Disabled compression and deprecated ciphers in OpenSSL library
- Improved security of Linux kernel and userspace
- Improved security of HTTP(S)
- Improved security of cookies
- Improved security and interoperability of IPsec
- Fixed setting of Perfect Forward Secrecy in IPsec
- Upgraded library OpenSSL to version 1.1.1l
- Upgraded program curl to version 7.79.1

## v6.3.1 (2021-07-21)

- Added support of setting MTU and MRU to PPTP configuration
- Added support of setting MTU and MRU to L2TP configuration
- Increased number of firewall rules from 8 to 16
- Fixed checking IPsec SA for multiple tunnels with same IDs
- Fixed WiFi interface statistics
- Fixed CVE-2020-24586 in Linux kernel
- Fixed CVE-2020-24587 in Linux kernel
- Fixed CVE-2020-24588 in Linux kernel
- Fixed CVE-2020-26139 in Linux kernel
- Fixed CVE-2020-26147 in Linux kernel
- Upgraded program dhcp-isc to version 4.1-ESV-R16-P1
- Upgraded program curl to version 7.78.0
- Upgraded program strongSwan to version 5.9.3

## v6.3.0 (2021-05-07)

- Added support of Multi SSID
- Added support of route-based VPN to IPsec
- Added support of certificate-chain validation in IPsec
- Added support of certificate revocation check to IPsec
- Changed remote syslog to use standard RFC 3164 format
- Upgraded program OpenSSH to version 8.5p1
- Upgraded program OpenVPN to version 2.4.11
- Upgraded program dnsmasq to version 2.85
- Upgraded program strongSwan to version 5.9.2

## v6.2.9 (2021-04-07)

- Added programs "basename", "cut", "dirname", "printf", "readlink" and "realpath"
- Added JavaScript validation of string inputs
- Upgraded library OpenSSL to version 1.1.1k
- Upgraded program curl to version 7.76.0
- Upgraded program ftpd to version 2.0

## v6.2.8 (2021-02-19)

- Added support of tls-crypt mode to OpenVPN configuration
- Added support of setting local IP address to GRE configuration
- Added ability to restrict HTTPS to TLS 1.3
- Added program doas as a replacement for program sudo
- Enabled automatic reboot when all memory is exhausted
- Enabled authoritative mode of DHCP server for WiFi clients
- Fixed resolving of IP address in OpenVPN
- Fixed possible reflected XSS attack
- Upgraded library OpenSSL to version 1.1.1j
- Upgraded program curl to version 7.74.0
- Upgraded program dnsmasq to version 2.84

## v6.2.7 (2020-12-17)

- Added support of Short GI to WiFi AP configuration
- Added support of Hardware UUID
- Added logging of user authentication failure when accessing the web interface
- Improved permission checking when executing commands like "status"
- Enabled support of POSIX message queues in Linux kernel
- Fixed importing encrypted key from file
- Fixed CVE-2020-25705 in Linux kernel
- Upgraded library OpenSSL to version 1.1.1i
- Upgraded program OpenVPN to version 2.4.10
- Upgraded pam_tacplus plugin to version 1.6.1

## v6.2.6 (2020-09-11)

- Added description field for each FW and NAT rule
- Enabled support of VRF Lite in Linux kernel
- Enabled support of UNIX98 pseudoterminals
- Fixed rare issue when restarting SNMP service
- Upgraded program dnsmasq to version 2.82

## v6.2.5 (2020-06-13)

- Added support for 802.1X authentication via Ethernet interfaces
- Changed password encryption method from MD5 to SHA256
- Increased maximum number of parameters in a configuration file to 1000
- Disabled autocomplete of password fields
- Hidden sensitive information in web interface
- Fixed crashing of Linux kernel unaligned memory access
- Fixed detection of MRAM during startup
- Upgraded program strongSwan to version 5.8.4

## v6.2.4 (2020-04-25)

- Added support of SHA384 to IPsec
- Added configuration of restraints for FTP and Telnet
- Added configuration of minimum TLS protocol version
- Added information about misaligned memory access to the report file
- Fixed crashing of Linux kernel during WiFi communication
- Fixed information about flags of bridges interfaces
- Fixed CVE-2019-5108 in Linux kernel
- Fixed CVE-2019-18282 in Linux kernel
- Fixed CVE-2020-8597 in program pppd
- Fixed CVE-2018-5388 in program strongSwan
- Fixed CVE-2018-10811 in program strongSwan
- Upgraded program OpenVPN to version 2.4.9
- Upgraded program dhcpcd to version 7.2.5
- Upgraded program dnsmasq to version 2.81
- Upgraded program ftpd to version 1.9.4
- Upgraded program sudo to version 1.8.31

## v6.2.3 (2020-02-11)

- Added checking of DPD delay and DPD timeout in IPsec configuration
- Reworked restarting WiFi so AP and STA are started independently
- Disabled reverse IP lookup in PAM RADIUS plugin
- Disabled reverse IP lookup in FTP server
- Fixed several bugs in VRRP
- Fixed restoring default configuration when RST button is pressed during boot sequence

## v6.2.2 (2019-12-16)

- Added programs "snmpget" and "snmpset"
- Added support of PAM TACACS+ authentication
- Added taking over of server users during RADIUS/TACACS+ authentication
- Changed format of transferred data in output of "status -v" command
- Increased maximum number of pending TCP connections in HTTP server
- Fixed detection of link status in Ethernet driver
- Fixed memory access failure when executing programs
- Fixed routing packets over IPsec with overlapping subnets
- Fixed establishing of L2TP tunnel
- Fixed CVE-2019-16275 in program hostapd
- Upgraded program curl to version 7.67.0

## v6.2.1 (2019-10-16)

- Added support of inotify for monitoring filesystem events
- Added support of 64-bit traffic counters
- Fixed memory access failure when executing programs
- Fixed access to FTP/PPTP server behind NAT
- Fixed crashing of PPTP client
- Fixed setting of Ethernet PHY
- Fixed CVE-2019-16746 in Linux kernel
- Fixed CVE-2019-17133 in Linux kernel
- Upgraded library OpenSSL to version 1.0.2t
- Upgraded library libpcap to version 1.9.1
- Upgraded program tcpdump to version 4.9.3

## v6.2.0 (2019-08-16)

- Added support of load balancing
- Added support of interface selection to PPPoE client
- Added support of IEEE 802.1Q to PPPoE client
- Added support of PAM RADIUS authentication
- Added support of loading certificates in PEM format
- Added support of loading certificates in PKCS#12 format
- Added support of VRRPv3 and the second instance
- Changed look of the web interface
- Applied toolchain hardening
- Disabled insecure services in default configuration
- Fixed netmask validation
- Upgraded Linux kernel to version 4.14.138
- Upgraded library glibc to version 2.30
- Upgraded program OpenVPN to version 2.4.7
- Upgraded program curl to version 7.65.3
- Upgraded program sudo to version 1.8.22
- Upgraded program iptables to version 1.4.21
- Upgraded program iproute2 to version 4.14.1
- Upgraded program iw to version 4.14
- Upgraded program hostapd to version 2.9
- Upgraded program wpa_supplicant to version 2.9

## v6.1.10 (2019-07-02)

- Added protection against brute force attacks
- Added filtering out of sensitive data from the report
- Added support of backup and restore of encrypted configuration
- Added support of dynamic starting time of automatic update
- Added dropping SYN packets with suspicious MSS value
- Extended compatibility check of uploaded user modules
- Enabled OpenVPN management interface
- Fixed route selection in Multi WAN mode
- Fixed CVE-2019-11477 in Linux kernel
- Fixed CVE-2019-11478 in Linux kernel

## v6.1.9 (2019-04-23)

- Added program "nohup"
- Added program "report"
- Added program "umupdate"
- Added possibility to set timeout for checking connection
- Added possibility to set port range to Firewall and NAT configuration
- Added information about additional interfaces into SNMP
- Modified comparison of firmware versions
- Fixed JavaScript on page SMTP Configuration
- Fixed kernel crash after change of bridge configuration
- Upgraded library OpenSSL to version 1.0.2r
- Upgraded program OpenSSH to version 8.0p1
- Upgraded program curl to version 7.64.1
- Upgraded program dnsmasq to version 2.80
- Upgraded program hostapd to version 2.8
- Upgraded program wpa_supplicant to version 2.8

## v6.1.8 (2018-11-08)

- Added command "sync"
- Added logging of user actions
- Added configuration of syslog service
- Added support of uploading HTTPS certificate
- Added support of mirroring network traffic
- Added information about product type into program "status"
- Added information about expected range of values to web interface
- Fixed selection of PSK for IKEv1 Main Mode
- Fixed crashing of DHCP client
- Fixed CVE-2018-14526 in program wpa_supplicant
- Upgraded library OpenSSL to version 1.0.2p
- Upgraded program BusyBox to version 1.29.3
- Upgraded program Net-SNMP to version 5.8
- Upgraded program OpenSSH to version 7.9p1
- Upgraded program curl to version 7.62.0

## v6.1.7 (2018-07-25)

- Added digital signature of firmware
- Added match extension "policy" to iptables
- Added new options to program "led"
- Added support of DNS configuration to PPPoE
- Modified validation of netmask
- Modified selection of local IP address for IPsec tunnels
- Fixed selection of SNMP trap agent-addr
- Upgraded library OpenSSL to version 1.0.2o
- Upgraded program curl to version 7.61.0

## v6.1.6 (2018-03-11)

- Added support of GCM ciphers to IPsec
- Added support of ECP DH groups to IPsec
- Added support of XAUTH to IPsec
- Added support of PubKey to IPsec
- Added support of IKEv2 reauthentication IPsec
- Added program "split"
- Added list of opened TCP and UDP sockets to the report file
- Added information from installed user modules to the report file
- Allowed using special characters in password for new user account
- Increased watchdog timeout
- Improved emergency reboot in case of unrecoverable kernel failure
- Improved throughput of the second Ethernet
- Fixed multiple issues in the second Ethernet driver
- Fixed multiple issues in FLASH driver
- Fixed MAC address in SNMP in case of active VRRP
- Fixed static routes via PPPoE and bridged interfaces
- Fixed CVE-2017-18017 in Linux kernel
- Upgraded program curl to version 7.58.0
- Upgraded program dhcp-isc to version 4.1-ESV-R15-P1

## v6.1.5 (2017-12-19)

- Added protocols GRE and ESP to firewall configuration
- Added emergency reboot in case of unrecoverable kernel failure
- Improved compatibility of IKEv2 protocol
- Hidden sensitive information in web interface
- Fixed WPA2 vulnerabilities
- Fixed detection of USB device speed
- Fixed memory leaks in processing fragmented packets
- Fixed multiple issues in the second Ethernet driver
- Upgraded firmware in WiFi module to version 0.36
- Upgraded library OpenSSL to version 1.0.2n
- Upgraded program OpenSSH to version 7.6p1
- Upgraded program curl to version 7.57.0
- Upgraded program dnsmasq to version 2.78
- Upgraded program hostapd to version 2.6
- Upgraded program wpa_supplicant to version 2.6

## v6.1.4 (2017-09-27)

- Added timestamps to the kernel log
- Added list of installed user modules to report file
- Added program "top"
- Enabled resizing of "vi" editor window
- Fixed IPsec tunnel termination
- Fixed IPsec tunnel checking mechanism
- Fixed removing iptables rules after IPsec termination
- Fixed routing of the second subnet over IPsec tunnel
- Fixed restarting of SSH server
- Fixed crash of EHCI driver
- Upgraded program OpenVPN to version 2.3.18
- Upgraded program tcpdump to version 4.9.2

## v6.1.3 (2017-08-10)

- Added protection against Clickjacking and XSS attacks
- Added wait for firmware update finish to program "reboot"
- Added match extension "statistic" to iptables
- Disabled renegotiation of SSL connection
- Fixed occasional freezing of backup routing daemon
- Fixed multiple issues in WiFi driver
- Fixed setting TX power on WiFi
- Fixed GRE tunnel initialization
- Fixed IPsec tunnel termination
- Upgraded program OpenVPN to version 2.3.17
- Upgraded program tcpdump to version 4.9.1

## v6.1.2 (2017-06-12)

- Added support of generic CDC-ECM devices
- Added automatic hiding of absent Ethernet interfaces
- Added target "TCPMSS" and match extension "tcpmss" to iptables
- Added programs "cmp", "head" and "wc"
- Added filtering of uploaded files by extension
- Added compatibility check of uploaded user modules
- Changed IKEv1 payload order due to better interoperability
- Fixed occasional freezing of communication over WiFi
- Fixed terminating of L2TP tunnel
- Fixed terminating of program "nc"
- Fixed CVE-2016-10229 in Linux kernel
- Downgraded program iproute2 to version 3.5.0
- Upgraded program OpenVPN to version 2.3.15
- Upgraded program strongSwan to version 5.5.3
- Upgraded program iw to version 3.5
- Upgraded library zlib to version 1.2.11

## v6.1.1 (2017-03-09)

- Added support of static routes
- Added support of backing up and restoring of user accounts
- Added support of L2TP in Linux kernel
- Added match extension "string" to iptables
- Improved security of cookies that are sent over HTTPS connection
- Modified storing content of text areas
- Fixed automatic update of firmware
- Fixed setting of IDs in IPsec when distinguished name is used
- Fixed redirecting services to non-defaults ports
- Fixed buffer overflow in program "status"
- Fixed CVE-2017-5970 in Linux kernel
- Fixed CVE-2017-6214 in Linux kernel
- Upgraded program tcpdump to version 4.9.0
- Upgraded program OpenSSH to version 7.4p1
- Upgraded library OpenSSL to version 1.0.2k
- Upgraded library glibc to version 2.25

## v6.1.0 (2016-12-15)

- Added support of IKEv2 for IPSec VPN
- Added support of authentication on Ethernet
- Added support of forcing NAT Traversal
- Added support of EAP-TLS authentication on WiFi
- Added support of SCP protocol
- Added support of HTTP server configuration
- Added support of SSH server configuration
- Added program "stty"
- Added target "NFQUEUE" to iptables
- Fixed memory exhaustion in SSH server
- Fixed termination of SSL connection in HTTP server

## v6.0.3 (2016-12-08)

- Upgraded program curl to version 7.51.0
- Upgraded program dnsmasq to version 2.76

## v6.0.2 (2016-10-21)

- Added license information
- Added showing error message for unsupported WiFi channels
- Fixed selecting bridged interface with dynamic IP address as backup route
- Fixed priorities for selecting backup route
- Fixed CVE-2016-7117 in Linux kernel
- Upgraded program conntrack-tools to version 1.0.1
- Upgraded library libnetfilter_conntrack to version 1.0.1
- Upgraded library libnfnetlink  to version 1.0.1
- Upgraded library glibc to version 2.24
- Upgraded library OpenSSL to version 1.0.2j

## v6.0.1 (2016-09-07)

- Added filtering out all forwarded invalid RST and FIN packets
- Reworked firmware update progress indicator
- Increased size of ICMP packets for checking connection
- Fixed turning on SIM LED after router power up
- Fixed handling premature disconnection of HTTP client
- Fixed reading statistics via SNMP protocol
- Upgraded program OpenSSH to version 7.3p1
- Upgraded program curl to version 7.50.1

## v6.0.0 (2016-06-29)

- Added support of client isolation on WiFi
- Added support of client authentication on WiFi
- Added support of Multiple WAN
- Removed support of "Extra Options" from IPsec configuration
- Removed program setkey
- Reworked configuration and starting VPN tunnels
- Upgraded program iproute to version 3.12.0

## v5.3.6 (2016-05-31)

- Updated WiFi regulatory database
- Removed support of WiFi channel 14
- Fixed processing of long response from DynDNS server
- Fixed setting community for 2nd SNMP user after firmware upgrade
- Upgraded program OpenVPN to version 2.3.11
- Upgraded library OpenSSL to version 1.0.2h

## v5.3.5 (2016-05-03)

- Optimized firmware update
- Changed parameters for generating HTTPS certificates (V3, SHA2, RSA-2048)
- Disabled weak cipher RC4 in HTTPS server
- Fixed potential vulnerability in HTTP(S) server
- Fixed login to router from R-WebDog system
- Fixed initialization of 4th IPsec tunnel
- Fixed CVE-2014-8160 in Linux kernel
- Fixed CVE-2014-8709 in Linux kernel
- Fixed CVE-2015-5364 in Linux kernel
- Fixed CVE-2015-5366 in Linux kernel
- Fixed CVE-2016-0821 in Linux kernel
- Upgraded program dhcp-isc to version 4.1-ESV-R13
- Upgraded program OpenSSH to version 7.2p2
- Upgraded library OpenSSL to version 1.0.1t

## v5.3.4 (2016-03-10)

- Modified firmware name check before update
- Fixed redirect after login
- Fixed unpacking tar archives with long filenames
- Upgraded library glibc to version 2.23
- Upgraded library OpenSSL to version 1.0.1s

## v5.3.3 (2016-02-12)

- Fixed JFFS2 corruption after read or write failure
- Fixed processing of IPSec packets when subnets are overlapping each other
- Upgraded program dhcp-isc to version 4.1-ESV-R12-P1
- Upgraded program OpenSSH to version 7.1p2
- Upgraded library OpenSSL to version 1.0.1r

## v5.3.2 (2015-12-10)

- Added target "CONNMARK" and match extension "connmark" to iptables
- Fixed regression in command "mount"
- Fixed missing CSRF token check
- Fixed redirect back to "LAN Configuration" page after applying changes

## v5.3.1 (2015-10-26)

- Changed absolute URLs to relative in HTTP redirects
- Fixed order of selectable backup routes in backward compatible mode
- Fixed restoring configuration from partial backup

## v5.3.0 (2015-10-13)

- Added support of 4 OpenVPN tunnels
- Added support of DHCP server on all LAN ports
- Added support of bridge in backup routes
- Added support of multiuser access
- Added CSRF attack protection
- Added passing variables SERVER_ADDR  and SCRIPT_NAME to executed CGI scripts
- Enabled support of high resolution timers in the kernel
- Changed ARP behaviour (arp_ignore=1, arp_announce=2)
- Modified router login page
- Modified firmware update page
- Fixed regression in command "killall"
- Fixed starting IPsec tunnels under heavy load
- Upgraded program OpenSSH to version 7.1p1
- Upgraded program OpenVPN to version 2.3.8
- Upgraded program Openswan to version 2.6.43.1
- Upgraded program Net-SNMP to version 5.7.3

## v5.2.1 (2015-07-17)

- Prohibited processing DNS TCP request from WAN
- Fixed rebinding DHCP lease after carrier loss
- Fixed termination of OpenVPN tunnel
- Fixed stopping VRRP daemon when multiple instances are running
- Downgraded program dhcpcd to version 6.4.7
- Upgraded program dnsmasq to version 2.73
- Upgraded program hostapd to version 2.4
- Upgraded program wpa_supplicant to version 2.4
- Upgraded library OpenSSL to version 1.0.1p

## v5.2.0 (2015-06-09)

- Added support of second SNMP user
- Added support of caching static files
- Added target "DSCP" and match extension "dscp" to iptables
- Disabled weak ciphers CBC and RC4 in SSH server
- Disabled weak ciphers CBC, RC4, SEED, CAMELLIA and IDEA in HTTPS server
- Fixed CVE-2013-4345 in Linux kernel
- Fixed CVE-2013-4348 in Linux kernel
- Fixed CVE-2013-7027 in Linux kernel
- Fixed CVE-2014-2706 in Linux kernel
- Fixed CVE-2015-3294 in program dnsmasq
- Fixed potential vulnerability in parsing malformed HTTP request
- Fixed regression in command "ip addr show" that stopped showing IP addresses
- Fixed separation of HTTP headers to comply with RFC 2616
- Fixed filtering of VRRP packets in firewall
- Fixed checking of type of recevied VRRP packets
- Fixed sending of gratuitous ARP packets at state transitions
- Upgraded program BusyBox to version 1.23.2
- Upgraded program OpenSSH to version 6.8p1
- Upgraded program OpenVPN to version 2.3.6
- Upgraded program curl to version 7.42.1
- Upgraded program dhcp-isc to version 4.1-ESV-R11
- Upgraded program dhcpcd to version 6.8.2
- Upgraded program ppp to version 2.4.7
- Upgraded program tcpdump to version 4.7.4
- Upgraded library gmp to version 6.0.0a
- Upgraded library lzo to version 2.09
- Upgraded library pcap to version 1.7.3
- Upgraded library zlib to version 1.2.8
- Replaced program arp with BusyBox applet
- Replaced program brctl with BusyBox applet
- Replaced program vconfig with BusyBox applet

## v5.1.3 (2015-04-24)

- Downgraded OpenSSL to version 1.0.1m

## v5.1.2 (2015-04-09)

- Upgraded OpenSSL to version 1.0.2a

## v5.1.1 (2015-04-01)

- Fixed loading WiFi configuration from alternative profiles

## v5.1.0 (2015-03-16)

- Added support of SHA256 and SHA512 in IPsec tunnels
- Added support of IPsec BEET mode into kernel
- Added parameter "Protocol/Port" to IPsec tunnel configuration
- Added parameter "Inactivity Timeout" to expansion port configuration
- Added selective flush of conntrack table after switching backup route
- Added locking mechanism to avoid multiple start of firmware update
- Added mechanism to recover from deleting configuration
- Added library libstdc++.so
- Fixed 5-bits and 6-bits mode on serial line
- Upgraded OpenSSL to version 1.0.2
- Upgraded glibc to version 2.21
- Upgrade iproute2 to version 3.5.0

## v5.0.0 (2014-12-02)

- Added support of SMTPS
- Added support of chaning SMTP port
- Added support of downloading firmware and configuration from HTTPS/FTPS server
- Added SSH klient
- Added SFTP server
- Added program "curl"
- Added program "find"
- Added program "fwupdate"
- Added program "ip rule"
- Added program "nc"
- Added program "netstat"
- Added program "pidof"
- Added program "xargs"
- Added information about product type into report
- Added automatic closing of SSH connection after 10 minutes of inactivity
- Reduced number of concurrent unauthenticated SSH connections and authentication attempts
- Disabled SSLv3 support in HTTPS protocol
- Enabled change of WEP default key index for WiFi STA mode
- Fixed getting of MAC address of interface eth0 if VRRP is enabled
- Upgraded WPA Supplicant to version 2.0

## v4.0.1 (2014-08-21)

- Added support of connecting to WiFi network with hidden SSID
- Added blocking of incoming traffic on all non-selected backup routes
- Added library libm.so
- Added filesystem devtmpfs
- Reduced SSH login timeout to 1 minute
- Removed unnecessary erasing of FLASH during firmware update
- Fixed function of XC-ETH in second expansion slot
- Fixed initialization of timer for MACB controller
- Fixed receiving data from serial line
- Fixed checking of PPPoE backup route
- Fixed NAT traversal support that was mistakenly removed from Openswan
- Upgraded ppp to version 2.4.6

## v4.0.0 (2014-04-15)

- Added support of WiFi
- Added support of multicast on GRE tunnels
- Added password check when remote access is enabled
- Added passing of interface name to scripts ip-up and ip-down in user modules
- Enhanced configuration of firewall
- Modified reading of temperature and supply voltage via SNMP protocol
- Modified displaying of timestamps on page DHCP Status
- Modified value of enterprise OID in SNMP traps
- Disabled remote access via SNMP in default configuration
- Prohibited processing DNS request incoming from WAN
- Removed router identification during login process
- Fixed identification of backup route parameter change
- Fixed VRRP initialization
- Fixed processing of IPSec packets when subnets are overlapping each other
- Upgraded kernel to version 3.5.0
- Upgraded OpenSSL to version 1.0.1g
- Upgraded OpenSSH to version 6.4p1
- Upgraded OpenVPN to version 2.3.3
- Upgraded OpenSWAN to version 2.6.41
- Upgraded dhcpcd to version 6.2.1
- Upgraded dnsmasq to version 2.68
- Upgraded ftpd to version 1.9.2
- Upgraded ppp to version 2.4.5
- Upgraded pptp to version 1.8.0
- Upgraded pptpd to version 1.4.0
- Upgraded tcpdump to version 4.5.1

## v3.0.9 (2013-11-20)

- Added program "getty"
- Added support of overriding values from DHCP by settings from configuration
- Added support of PPTP passthrough
- Added temperature and supply voltage to SNMP traps
- Added displaying of network interface flags
- Added passing variables REMOTE_ADDR, REMOTE_USER and HTTP_COOKIE to executed CGI scripts
- Removed deleting of all iptables rules after configuration change
- Removed logging of some unimportant warning of program l2tpd
- Fixed bug with long period for connection check after reboot
- Fixed starting of IPsec and OpenVPN tunnels after backup route change

## v3.0.8 (2013-08-30)

- Added match extension "pkttype" to iptables
- Added passive check of TCP keepalive expiration
- Added delay before reopening serial line after failure
- Modified indication of installed XC-SW expansion board
- Fixed decoding of invalid BCD values read out by MBUS protocol
