9.2.5.2.19SF-HW: 1. Toolchain: binutils version is upgraded 2.37->2.38. 2. Toolchain: Go is upgraded 1.17.6->1.17.7. 3. util-linux package is upgraded 2.37.2->2.37.4 (fixing CVE-2021-3995, CVE-2021-3996, CVE-2022-0563). 4. expat package is upgraded 2.4.3->2.4.6 (fixing CVE-2022-23852, CVE-2022-23990). 5. aws-iot: add possibility to disable Amazon Alexa (@NetBytes, @spocko): nvram set noaws=1 nvram commit reboot 6. iptables: add patch to disable exit if no library for match (@HELLO_wORLD). 7. dnscrypt-proxy-2: change startup priority to 98 (@microchip). 8. unbound package (used in stubby) is upgraded 1.14.0->1.15.0. 9. bind package is upgraded 9.17.21->9.18.0. 10. libusb package is upgraded 1.0.24->1.0.25. 11. iperf3 package is upgraded 3.10.1->3.11. 12. nano package is upgraded 6.0->6.2. 13. GNU 'less' utility is added, busybox applet 'less' is disabled (to support UTF-8). 14. '-O3' optimization for part of drivers (kernel level). 9.2.5.2.18.1SF-HW: 1. expat package is upgraded 2.4.2->2.4.3 (fixing CVE-2021-45960, CVE-2021-46143, from CVE-2022-22822 to CVE-2022-22827). Base Scores: 7.5, 7.8/8.1, 9.8, 9.8, 9.8, 8.8, 8.8, 8.8. https://github.com/libexpat/libexpat/blob/R_2_4_3/expat/Changes 2. nano: add UTF-8 support. 3. lighttpd package is upgraded 1.4.63->1.4.64. 4. ethtool package is upgraded 5.15->5.16. 5. Host tools: upgrade mtd-utils to 2.1.4. 9.2.5.2.18SF-HW: 1. Toolchain: Go is upgraded 1.17.5->1.17.6. 2. OpenSSL v. 1.1.1 package is upgraded 1.1.1l->1.1.1m. 3. OpenVPN is upgraded 2.5.4->2.5.5. 4. unbound package (used in stubby) is upgraded 1.13.2->1.14.0. 5. getdns package (used in stubby) is upgraded 1.5.2->1.7.0. 6. Add 'check' package ('getdns' dependency). 7. stubby package is upgraded 0.3.0->0.4.0. 8. curl package is upgraded 7.80.0->7.81.0. 9. elfutils package is upgraded 0.182->0.186. 10. libnl-tiny package is upgraded 2020-08-05->2021-11-21. 11. libexif package is upgraded 0.6.22->0.6.24. 12. e2fsprogs package is upgraded 1.46.4->1.46.5. 13. haveged package is upgraded 1.9.15->1.9.17. 14. expat package is upgraded 2.4.1->2.4.2. 15. dbus package is upgraded 1.13.18->1.13.20. 16. bind package is upgraded 9.17.20->9.17.21. 17. nano package is upgraded 5.9->6.0. 18. hd-idle package is upgraded 1.04->1.05. 19. dnscrypt-proxy-2: add UPX packing. 20. Added new user's script for V2 user using the Bitdefender mount (supajason). 21. Host tools: upgrade e2fsprogs to 1.46.5. 22. Host tools: upgrade scons to 3.1.2. 23. Host tools: upgrade mkimage/u-boot to 2021.10. 9.2.5.2.17SF-HW: 1. Toolchain: Go is upgraded 1.17.2->1.17.5. 2. Toolchain: gdb is upgraded 10.1->11.1. 3. Fix lacking build of 'kmod-ipt-ipset' (ipset). 4. wireguard package is upgraded 1.0.20210606->1.0.20211208. 5. lighttpd package is upgraded 1.4.61->1.4.63. 6. curl package is upgraded 7.79.1->7.80.0. 7. iproute2 package is upgraded 4.0.0->4.4.0. 8. xtables-addons package is upgraded 2.10->2.14. 9. ethtool package is upgraded 5.14->5.15. 10. iw package is upgraded 5.9->5.16. 11. ncurses package is upgraded 6.2->6.3. 12. ca-certificates package is upgraded 20210119->20211016. 13. bind package and its dependences libuv/nghttp2 are added ('dig' command). 14. Default congestion control algorithm is changed to 'highspeed'. 15. HTCP/ILLINOIS congestion control algorithms are added. 16. Slight optimization of some components. 17. Host tools: various updates. 9.2.5.2.16SF-HW: 1. Toolchain: Go is upgraded 1.17->1.17.2. 2. wireguard-tools package is upgraded 1.0.20210424->1.0.20210914. 3. DNSCrypt Proxy v.2 is upgraded 2.1.0->2.1.1. 4. OpenVPN is upgraded 2.5.3->2.5.4. 5. wget package is upgraded 1.21.1->1.21.2. 6. lighttpd package is upgraded 1.4.59->1.4.61. 7. proftpd package is upgraded 1.3.7b->1.3.7c. 8. bridge-utils package is upgraded 1.7->1.7.1. 9. curl package is upgraded 7.78.0->7.79.1. 10. gdbm package is upgraded 1.19->1.19.1. 11. cifs-utils package is upgraded 6.13->6.14. 12. coreutils package (sort/gnu-date) is upgraded 8.32->9.0. 13. haveged package is upgraded 1.9.14->1.9.15. 14. ethtool package is upgraded 5.13->5.14. 15. nano package is upgraded 5.8->5.9. 16. jansson package is upgraded 2.13.1->2.14. 17. libiconv-full package is upgraded 1.11.1->1.16. 18. Fix build by GCC 10.x (Host Debian Buster->Host Debian Bullseye). 19. Kernel level optimization. 20. iptables: synchronize with LBR20, add missed mods. 21. Host tools: upgrade bison to 3.8.2. 9.2.5.2.15SF-HW: 1. Toolchain: Go is upgraded 1.16.6->1.17. 2. OpenSSL v. 1.1.1 package is upgraded 1.1.1k->1.1.1l (fixing CVE-2021-3711, CVE-2021-3712). Base Scores (SUSE): 9.8 and 5.3. 3. DNSCrypt Proxy v.2 is upgraded 2.0.45->2.1.0. See https://github.com/DNSCrypt/dnscrypt-proxy/releases re: what to change in your config 4. ipset package is upgraded 7.14->7.15. 5. procps-ng package is upgraded 3.3.16->3.3.17. 6. elfutils package is upgraded 0.180->0.182. 7. pcre package is upgraded 8.44->8.45. 8. libpcap package is upgraded 1.10.0->1.10.1. 9. util-linux package is upgraded 2.37.1->2.37.2. 10. unbound package (used in stubby) is upgraded 1.13.1->1.13.2. 11. e2fsprogs package is upgraded 1.46.3->1.46.4. 12. OpenVPN client init script: fix bash style comparison '==' -> '='. 13. Fix ez-ipupdate compilation (synchronize with LBR20). 14. Syncronize dropbear init script with LBR20 (net-wall call). 15. Change 'net-util' to avoid TrendMicro cron update schedule (R8900/R9000 specific). 16. Host tools (e2fsprogs): is upgraded to 1.46.4. 9.2.5.2.14SF-HW: 1. Toolchain: binutils version is upgraded 2.36.1->2.37. 2. Toolchain: Go is upgraded 1.16.5->1.16.6. 3. QCA drivers/firmware are upgraded (integration from V2.7.3.22 stock). 4. wireguard-tools: add PresharedKey support to WireGuard client. 5. OpenVPN is upgraded 2.5.2->2.5.3. 6. curl package is upgraded 7.77.0->7.78.0. 7. proftpd package is upgraded 1.3.7a->1.3.7b. 8. gettext-full package is upgraded 0.19.8.1->0.21. 9. ethtool package is upgraded 5.12->5.13. 10. ipset package is upgraded 7.11->7.14. 11. e2fsprogs package is upgraded 1.46.2->1.46.3. 12. util-linux package is upgraded 2.37->2.37.1. 13. Change WebGUI logo. 14 Kernel: Use FSCACHE as a kernel module. 15. Host tools (e2fsprogs): is upgraded to 1.46.3. 9.2.5.2.13SF-HW: 1. Toolchain: GCC is upgraded 9.3.0->9.4.0. 2. Toolchain: Go is upgraded 1.16.3->1.16.5. 3. wireguard package is upgraded 1.0.20210424->1.0.20210606. 4. curl package is upgraded 7.76.1->7.77.0 (fixing CVE-2021-22897, CVE-2021-22898, CVE-2021-22901). 5. expat package is upgraded 2.2.10->2.4.1 (fixing CVE-2013-0340). 6. ethtool package is upgraded 5.10->5.12. 7. util-linux package is upgraded 2.36.2->2.37. 8. iperf3 package is upgraded 3.9->3.10.1. 9. nano package is upgraded 5.6.1->5.8. 10. Slight optimization of some components. 9.2.5.2.12SF-HW: 1. Toolchain: Go is upgraded 1.16.2->1.16.3. 2. wireguard package is upgraded 1.0.20210219->1.0.20210424. 3. wireguard-tools package is upgraded 1.0.20210315->1.0.20210424. 4. OpenVPN is upgraded 2.5.1->2.5.2. 5. OpenSSL v. 1.1.1 package is upgraded 1.1.1j->1.1.1k (fixing CVE-2021-3449, CVE-2021-3450). 6. curl package is upgraded 7.75.0->7.76.1 (fixing CVE-2021-22876, CVE-2021-22890). 7. dbus package is upgraded 1.13.12->1.13.18 (fixing CVE-2020-12049, CVE-2020-35512). 8. cifs-utils package is upgraded 6.12->6.13 (fixing CVE-2021-20208). 9. haveged package is upgraded 1.9.13->1.9.14. 10. ipset: Kernel modules optimization '-O3'. 11. Kernel: Add BLK_DEV_LOOP and FUSE modules support 12. Toolchain: add optimization patch to uClibc. 9.2.5.2.11SF-HW: 1. Toolchain: Go is upgraded 1.16->1.16.2. 2. iptables: add iptables-mod-rpfilter plugin (HELLO_wORLD). 3. wireguard-tools package is upgraded 1.0.20210223->1.0.20210315. 4. cifs-utils package is upgraded 6.11->6.12. 5. libpcap package is upgraded 1.9.1->1.10.0. 6. e2fsprogs package is upgraded 1.45.6->1.46.2. 7. tar package is upgraded 1.32->1.34. 8. nano package is upgraded 5.6->5.6.1. 9. sysstat package is upgraded 12.4.2->12.4.3. 10. gdbm package is upgraded 1.18.1->1.19. 11. unzip: add security patches. 12. Kernel config: Add IP_NF_MATCH_RPFILTER/IP6_NF_MATCH_RPFILTER (iptables-mod-rpfilter). 13. Disable ARM/NEON acceleration (kernel crypto AES/SHA1) to avoid conflicts with QCE. 14. Host tools (e2fsprogs): is upgraded to 1.46.2. 9.2.5.2.10SF-HW: 1. Toolchain: Go is upgraded 1.15.7->1.16. 2. Toolchain: binutils version is upgraded 2.36->2.36.1. 3. Selective integration of 2.7.x.x: UA_Parser utility is updated to fix: CVE-2020-27861/PSV-2020-0301 https://nvd.nist.gov/vuln/detail/CVE-2020-27861 https://kb.netgear.com/000062507/Security-Advisory-for-Unauthenticated-Command-Injection-Vulnerability-on-Some-Extenders-and-Orbi-WiFi-Systems-PSV-2020-0301 (UA_Parser utility is taken from GPL sources V2.7.0.70) 4. OpenSSL v. 1.1.1 package is upgraded 1.1.1i->1.1.1j (fixing CVE-2021-23840 and CVE-2021-23841). https://nvd.nist.gov/vuln/detail/CVE-2021-23840 https://nvd.nist.gov/vuln/detail/CVE-2021-23841 5. Fix NG/DNI bug in net-lan for ReadyCLOUD ('alish.sh'->'alias.sh') (thanks to kamoj). 6. lighttpd package is upgraded 1.4.58->1.4.59. 7. wireguard package is upgraded 1.0.20210124->1.0.20210219. 8. wireguard-tools package is upgraded 1.0.20200827->1.0.20210223. 9. OpenVPN is upgraded 2.5.0->2.5.1. 10. ipset package is upgraded 7.10->7.11. 11. util-linux package is upgraded 2.36.1->2.36.2. 12. unbound package (used in stubby) is upgraded 1.13.0->1.13.1. 13. ca-certificates package is upgraded 20200601->20210119. 14. wget package is upgraded 1.20.3->1.21.1. 15. curl package is upgraded 7.74.0->7.75.0. 16. nano package is upgraded 5.5->5.6. 17. Selective optimization '-O3' of kernel components/modules (slight boost). 18. net-wall script: special processing IPv6 option 'net-wall -6 start' or 'net-wall -6 restart' (thanks to HELLO_wORLD). 19. Host tools: upgrade mkimage (u-boot) to 2018.03. 9.2.5.2.9SF-HW: 1. Toolchain: Go is upgraded 1.15.6->1.15.7. 2. Toolchain: binutils version is upgraded 2.35.1->2.36. 3. DNSCrypt Proxy v.2 is upgraded 2.0.44->2.0.45. (see https://github.com/DNSCrypt/dnscrypt-proxy/releases for details and changes in config). 4. wireguard package is upgraded 1.0.20201221->1.0.20210124. 5. iptables package is upgraded 1.8.6->1.8.7. 6. lighttpd package is upgraded 1.4.57->1.4.58. 7. ethtool package is upgraded 5.9->5.10. 8. sysstat package is upgraded 12.4.1->12.4.2. 9. ngrep package is upgraded 1.45->1.47. 10. nano package is upgraded 5.4->5.5. 11. libreadline package is upgraded 8.0->8.1. 12. tcpdump package is upgraded 4.5.1->4.9.3. 13. libpcap package is upgraded 1.5.3->1.9.1. 14. Fix NG/DNI 'igmpproxy' modified source codes (to provide compatibility with 'libpcap'). 15. samba36 package: optimize for a size. 16. Disable SOUND and FUSE_FS support (kernel config). 17. Optimize options for kernel compilation. 18. iprange 1.0.4 package is added (Aegis, HELLO_wORLD). 9.2.5.2.8SF-HW: 1. Toolchain: Go is upgraded 1.15.5->1.15.6. 2. OpenSSL v. 1.1.1 package is upgraded 1.1.1h->1.1.1i (fixing CVE-2020-1971). 3. curl package is upgraded 7.73.0->7.74.0 (fixing CVE-2020-8284, CVE-2020-8285, CVE-2020-8286). 4. wireguard package is upgraded 1.0.20201112->1.0.20201221. 5. OpenVPN is upgraded 2.4.9->2.5.0. 6. ipset package is upgraded 7.9->7.10. 7. lighttpd package is upgraded 1.4.56->1.4.57. 8. proftpd package is upgraded 1.3.6e->1.3.7a. 9. unbound package (used in stubby) is upgraded 1.12.0->1.13.0. 10. elfutils package is upgraded 0.179->0.180. 11. nano package is upgraded 5.3->5.4. 12. libusb package is upgraded 1.0.23->1.0.24. 13. logrotate package is upgraded 3.16.0->3.17.0. 14. tar package: optimize for a size. 15. Add procps-ng package utilities ('ps', 'top'). (run '/usr/bin/top-procps-ng' or '/usr/bin/ps-procps-ng -aux' from console to check them). 16. OpenVPN server: add 'CHACHA20-POLY1305' cipher to 'ncp-ciphers' option and change the cipher of downloaded config for Windows clients to 'CHACHA20-POLY1305'. (Important: it is highly recommended to use 'CHACHA20-POLY1305' if your client is based on v. 2.5.x, much faster, change your non-Windows client config if possible). 9.2.5.2.7.1SF-HW: 1. The button "Reset to factory default settings" is disabled. (See QuickStart.txt for details.) 2. Toolchain: gdb is upgraded 8.3.1->10.1. 3. Toolchain: make an order with binutils patches. 3. sysstat package is upgraded 12.4.0->12.4.1. 4. lighttpd package is upgraded 1.4.55->1.4.56. 9.2.5.2.7SF-HW: 1. Toolchain: Go is upgraded 1.15.3->1.15.5. 2. Fix NG/DNI busybox issue: 'date -r' command is fixed. 3. Fix NG/DNI bug/issue: 'config commits' -> 'config commit' (check_fwupgrade, soap_wifi_action.sh scripts). 4. Fix NG/DNI bug/issue: change 'dil' startup (fix segmentations fault and core dump on RBS). 5. Fix NG/DNI bug/issue: change 'dil_boot.sh' to use 'date' from coreutils ('date +%s%3N' does not work with busybox version of 'date'). 6. Add 'date' from coreutils (/usr/bin/gnu-date). 7. wireguard package is upgraded 1.0.20200908->1.0.20201112. 8. dropbear package is upgraded 2020.80->2020.81. 9. iptables package is upgraded 1.8.5->1.8.6. 10. ipset package is upgraded 7.6+ [2020-03-09]->7.9. 11. ipt-ipset (kernel modules) package is upgraded 7.6+ [2020-03-09]->7.9. 12. util-linux package is upgraded 2.36->2.36.1. 13. unbound package (used in stubby) is upgraded 1.11.0->1.12.0. 14. lz4 package (used in OpenVPN) is upgraded 1.9.2->1.9.3. 15. ethtool package is upgraded 5.8->5.9. 16. iw package is upgraded 5.4->5.9. 17. libnl-tiny package is upgraded 2019-10-29->2020-08-05. 18. curl package is upgraded 7.72.0->7.73.0. 19. Change samba components update_smb/update_smb.sh to do not try to start samba if disable in nvram. 20. Host tools: upgrade bison to 3.7.4. 21. Host tools: upgrade gmp to 6.2.1. 22. Host tools: upgrade mpc to 1.2.1. 9.2.5.2.6SF-HW: 1. Toolchain: Go is upgraded 1.14.7->1.15.3. 2. Toolchain: binutils version is upgraded 2.35->2.35.1. 3. Toolchain: -finline-functions compiler option is added to GCC. 4. Kernel level acceleration (-O2, -march=armv7-a -> -mcpu=cortex-a7, -finline-functions, etc.). 5. wireguard package is upgraded 1.0.20200729->1.0.20200908. 6. Change kernel config and OpenSSL 1.1.1 to allow using dynamic devcrypto and afalg engines (HW version). 7. OpenSSL v. 1.1.1 package is upgraded 1.1.1g->1.1.1h. 8. OpenSSL v. 1.0.2 package: change default config directory. 9. Fix Smart Lock icon issue (WebGUI). 10. jansson package is upgraded 2.12->2.13.1. 11. libjson-c package is upgraded 0.14->0.15. 12. expat package is upgraded 2.2.9->2.2.10. 13. nano package is upgraded 5.2->5.3. 14. Change SAMBA config generation (for Android/iOS gadgets, issue reported by Rustypouch). 15. Make an order in samba36 Makefile. 16. logrotate package is upgrader 3.15.0->3.16.0. 17. cifs-utils package is upgraded 6.10->6.11. 18. iperf3 package is upgraded 3.8.1->3.9. 19. Fix proftpd issue: display size of large file (thanks to R. Gerrits). 9.2.5.2.5.1SF-HW: 1. Toolchain: GCC is changed 10.2.0->9.3.0 (issue with IPv6 when using GCC 10.2.0). 2. wireguard-tools package is upgraded 1.0.20200820->1.0.20200827. 3. nano package is upgraded 5.1->5.2. 4. ethtool package is upgraded 5.4->5.8. 5. Host tools (mpc): is upgraded to 1.2.0. 9.2.5.2.5SF-HW: 1. Integration of changes from the stock v. 2.5.2.4. 2. Toolchain: Go is upgraded 1.14.6->1.14.7. 3. Toolchain: binutils is upgraded 2.34->2.35. 4. wireguard package is upgraded 1.0.20200712->1.0.20200729. 5. wireguard-tools package is upgraded 1.0.20200513->1.0.20200820. 6. unbound package (used in stubby) is upgraded 1.10.1->1.11.0. 7. net-lan init script is fixed (thanks to kamoj). 8. qcawifi.sh: Fix for guest Wi-Fi allowing DNS over TCP (thanks to R. Gerrits). 9. nano package is upgraded 4.9.3->5.1. 10. curl package is upgraded 7.71.1->7.72.0 (fixing CVE-2020-8231). 11. SAMBA: update config generation. 12. sysstat package is upgraded 12.2.2->12.4.0. 13. util-linux package is upgraded 2.35.2->2.36. 14. Host tools (bison): is upgraded to 3.7.1. 15. Host tools (mpfr): is upgraded to 4.1.0. 9.2.5.1.34SF-HW: 1. Toolchain: GCC is upgraded 9.3.0->10.2.0. 2. Toolchain: Go is upgraded 1.14.3->1.14.6. 3. inetd daemon binary: downgrade to version from the stock 2.5.1.16. 4. libjson-c 0.12.1 package: fix of CVE-2020-12762. 5. wireguard package is upgraded 1.0.20200623->1.0.20200712. 6. proftpd package is upgraded 1.3.6d->1.3.6e. 7. iperf3 package is upgraded 3.7->3.8.1. 8. haveged package is upgraded 1.9.12->1.9.13. 9. sysstat package is upgraded 12.2.1-12.2.2. 10. bridge-utils package is upgraded 1.6->1.7. 9.2.5.1.33SF-HW: 1. Integration of changes from the stock v. 2.5.1.32. 2. dropbear package is upgraded 2020.79->2020.80. 3. wireguard package is upgraded 1.0.20200601->1.0.20200623. 4. curl package is upgraded 7.70.0->7.71.1. 5. stubby package is upgraded 0.2.6->0.3.0. 6. yaml package (used in stubby) is upgraded 0.2.4->0.2.5. 7. haveged package is upgraded 1.9.8->1.9.12. 8. elfutils package is upgraded 0.161->0.179. 9. libjson-c package is upgraded 0.13.1->0.14 (including fix of CVE-2020-12762). 10. etherwake 1.09 package is added. 9.2.5.1.19SF-HW: 1. dropbear package is upgraded 2019.78->2020.79 (scp fix for CVE-2018-20685: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20685 support of ed25519 hostkeys and authorized_keys, adding chacha20-poly1305 authenticated cipher etc). 2. mount.cifs v. 6.10 utility is added (allowing to mount remote CIFS Share, see QuickStart.txt). 3. Kernel changes to allow mounting a CIFS Share. 4. iptables package is upgraded 1.8.4->1.8.5. 5. ca-certificates package is upgraded 20190110->20200601. 6. DNSCrypt Proxy v.2 is upgraded 2.0.42->2.0.44. 7. wireguard package is upgraded 1.0.20200520->1.0.20200601. 8. wireguard init script is changed (allowing to use LocalIP scope such as e.g. 10.0.xxx.xxx/24). 9. proftpd package is upgraded 1.3.6c->1.3.6d. 10. pcre package is upgraded 8.43->8.44. 11. Host tools: mkimage is downgraded (u-boot-2014.10). Probably this should fix TFTP issue but not tested yet. 9.2.5.1.18.1SF-HW: 1. "Reset to factory settings" option is temporary disabled in WebGUI. 9.2.5.1.18SF-HW: 1. net-wall script is fixed for ppp0 connection and modifyed to provide more safety (OpenVPN/WireGuard client, thanks to R. Gerrits). 2. DNSCrypt Proxy v.2 init script is fixed (time synchronization, thanks to kamoj). 3. Support of custom SAMBA config is added (see QuickStart.txt). 4. Automatic custom script execution after reboot is added (for ORBI RBK V2 owners, no USB port, see QuickStart.txt). 5. wireguard package is upgraded 1.0.20200413->1.0.20200520. 6. wireguard-tools package is upgraded 1.0.20200319->1.0.20200513. 7. ipset package is upgraded 7.4->7.6+ [2020-03-09]. 8. iptables package is upgraded 1.4.21->1.8.4. 9. curl package is upgraded 7.69.1->7.70.0. 10. dbus package is upgraded 1.12.12->1.13.12. 11. unbound package (used in stubby) is upgraded 1.9.6->1.10.1. 12. yaml package (used in stubby) is upgraded 0.2.2->0.2.4. 13. util-linux package is upgraded 2.35.1->2.35.2. 14. libreadline package is upgraded 6.3->8.0. 15. nano package is upgraded 4.9.2->4.9.3. 16. Toolchain: Go is upgraded 1.14.1->1.14.3. 17. Host tools (findutils): is upgraded to 4.7.0. 9.2.5.1.17SF-HW: 1. Integration of changes from the stock v. 2.5.1.16. 2. OpenVPN is upgraded 2.4.8->2.4.9 (CVE-2020-11810). https://openvpn.net/community-downloads/ 3. OpenSSL v. 1.1.1 package is upgraded 1.1.1e->1.1.1g (CVE-2020-1967). https://nvd.nist.gov/vuln/detail/CVE-2020-1967 4. DEV_show_device.htm is changed (Attached Device List selectable order, thanks to CrimpOn). 5. mkswap/swapon/swapoff busybox applets are added. 6. ipset package is upgraded 6.24->7.4. 7. ethtool package is upgraded 3.18->5.4. 8. wireguard package is upgraded 0.0.20200318->1.0.20200413. 9. nano package is upgraded 4.9->4.9.2. 10. Host tools (e2fsprogs): is upgraded to 1.45.6. 11. Host tools (xz): is upgraded to 5.2.5. 12. Host tools (mm-macros): is upgraded to 1.0.0. 13. Host tools (patchelf): is upgraded to 0.10. 14. Host tools (gengetopt): is upgraded to 2.23. 9.2.5.1.13.1SF-HW: 1. Toolchain: GCC is upgraded 5.5.0->9.3.0. 2. Toolchain: binutils version is upgraded 2.32->2.34. 3. Toolchain: Go is upgraded 1.13.8->1.14.1. 4. DEV_show_device.htm is changed (Attached Device List order by IP). 5. hotplug2: changes for WG client (config from USB flash, dos2unix). 6. nano package is added (editor). 7. wireguard package is upgraded 0.0.20200215->0.0.20200318. 8. wireguard-tools package is upgraded 1.0.20200206->1.0.20200319. 9. OpenSSL v. 1.1.1 package is upgraded 1.1.1d->1.1.1e. 10. DNSCrypt Proxy v.2 is upgraded 2.0.39->2.0.42. 11. e2fsprogs package is upgraded 1.45.5->1.45.6. 12. Changes in the Linux kernel and in many packages to provide compilation by GCC 9.3.0. 9.2.5.1.12.1SF-HW: 1. PPP vulnerability CVE-2020-8597 is fixed (score of 9.8/10). https://nvd.nist.gov/vuln/detail/CVE-2020-8597 2. proftpd package is upgraded 1.3.6->1.3.6c. 3. curl package is upgraded 7.68.0->7.69.1. 4. avahi package is upgraded 0.7->0.8. 5. ncurses package is upgraded 6.1->6.2. 9.2.5.1.12SF-HW: 1. OpenVPN client support is added (see QuickStart.txt). 2. Option in nvram to disable samba start is added. 3. hotplug2 package is changed to support copying WireGuard/OpenVPN client configs from USB flash drive. 4. wireguard package is upgraded 0.0.20200128->0.0.20200215. 5. wireguard-tools package is upgraded 1.0.20200121->1.0.20200206. 6. DNSCrypt Proxy v.2 is upgraded 2.0.38->2.0.39. 7. util-linux package is upgraded 2.35->2.35.1. 8. lighttpd package is upgraded 1.4.54->1.4.55. 9. libusb package is upgraded 1.0.22->1.0.23. 10. libusb-compat package is upgraded 0.1.5->0.1.7. 11. usb-modeswitch data is updated 20170806->20191128. 12. sysstat package is upgraded 11.0.4->12.2.1. 13. iw package is upgraded 5.3->5.4. 14. fdisk utility is added. 15. resize2fs utility is addded. 16. Host tools (quilt): is upgraded to 0.66. 17. Host tools (gmp): is upgraded to 6.2.0. 18. Host tools (sed): is upgraded to 4.8. 19. Host tools (bison): is upgraded to 3.5.1. 9.2.5.1.11SF-HW: 1. WireGuard client support is added (tested with Integrity VPN, thanks to KW.). 2. net-wall firewall is changed to support WireGuard client. 3. wireguard package is upgraded 0.0.20191226->0.0.20200128. 4. wireguard-tools package is upgraded 1.0.20191226->1.0.20200121. 5. e2fsprogs package is upgraded 1.44.5->1.45.5. 6. curl package is upgraded 7.67.0->7.68.0. 7. DNSCrypt Proxy v.2 build scheme is changed (compilation by Go, dynamic GCC libs). Should work faster. 8. DNSCrypt Proxy v.2 is upgraded to version 2.0.38. 9. pcre package is upgraded 8.38->8.43. 10. util-linux package is upgraded 2.34->2.35. 11. Host tools (e2fspogs): is upgraded to 1.45.5. 12. Host tools (make-ext4fs): us upgraded to 2020-01-05. 13. Host tools (bison): is upgraded to 3.5. 9.2.5.1.10SF-HW: 1. OpenSSL 1.0.2 is upgraded 1.0.2t->1.0.2u. 2. lighttpd package is upgraded 1.4.53->1.4.54. 3. lighttpd package is changed to use OpenSSL 1.1.1. 4. routerlogin.net certificate is added (you can access your Orbi GUI as https://routerlogin.net). 5. DnsCrypt Proxy v2 is upgraded to version 2.0.36. 6. logrotate package us upgraded 3.8.1->3.15.0. 7. WireGuard package is upgraded 20191219->20191226 (plus changes in build tree). 8. Option in nvram to disable xagent start is added. 9. parted package (and its dependences) is added (used in hotplug2). 10. Happy New Year! 9.2.5.1.9SF-HW: 1. Integration of changes from the stock v. 2.1.5.8. 2. WireGuard package is upgraded 20191212->20191219. 3. unbound package (used in stubby) is upgraded 1.9.5->1.9.6. 4. iw package is added. 5. Options in nvram to disable Armor (BitDefender) and Circle update daemons are added. 6. Huge Armor installation and update tarballs are removed to avoid oversize of firmware (cloud-like installation from https://www.voxel-firmware.com/, tarballs are moved to this site). 9.2.5.0.43SF-HW: 1. Support of HiLink modem (3G/LTE: in RNDIS/CDC mode) is added. 2. WireGuard v. 20191212 is added (kernel module + "wg" utility). 3. Issue with telnet login is fixed. 4. Dropbear (SSH) is changed to allow password login (use WebGUI password for "root" user). 5. DnsCrypt Proxy v2 is upgraded to version 2.0.35. 6. stubby config is changed (not so strict requirements to the server). 7. e2fsprogs: CVE-2019-5094 and specific DNI patches are added. 8. bzip2 package is upgraded to version 1.0.8 and enabled instead of busybox version. 9. curl package is upgraded 7.66.0->7.67.0. 10. libnl-tiny package is upgraded 0.1->2019-10-29. 11. proftpd package is upgraded 1.3.3->1.3.6 plus CVE-2019-12815 patch. 12. Several NG/DNI bugs are fixed. 13. 14 not used now packages are disabled. 14. Debug: Possibility to separate SSIDs (2.4GHz/5GHz). 15. Default Congestion Control Algorithm is changed to YeAH. 16. Host tools: 19 components are upgraded to allow compilation on Debian Buster. 17. Numeration of firmware is changed (starting from "9") to avoid firmware auto updates from NG (stock).