Mudi 7 / GL-E5800EU: USB RNDIS Code 10 after 4.10.0 OTA upgrade; 4.8.5 works

Hi everyone,

I would appreciate help investigating a regression in the Mudi 7’s built-in USB networking function.

Affected feature: The Mudi 7 shares its LAN/internet connection to a Windows PC over USB, using the router’s built-in RNDIS function. This is not a phone providing a USB WAN connection to the router.

Upgrade route and observed behavior

I upgraded to 4.10.0 through the Mudi 7’s built-in online update / OTA mechanism on 1 September 2026. I did not manually download and flash a beta image.

With 4.10.0, the Windows RNDIS device fails to start with Code 10, and USB networking is unusable. The issue also reproduces under stock settings.

Returning the same router to 4.8.5 release2, using the same respective cables and USB ports, restores operation on both Windows computers.

Test systems

Computer 4.10.0 4.8.5 release2
Windows 11 workstation — Pro 25H2, build 26200.9168 RNDIS Code 10; no usable USB networking Device starts and USB networking works; diagnostic verification is included
Windows 11 24H2 laptop — Pro 24H2, build 26100.7462 Same Code 10 failure Networking restored; these are my test observations

The physical connection is USB-A on the PC to the Mudi 7’s data-capable USB-C port.

On the workstation, the recorded driver is Microsoft rndiscmp.inf, version 10.0.26100.1, automatically bound. The device reports VID_2C7C / PID_0133, with CM_PROB_FAILED_START and Kernel-PnP status 0xC0000001.

The successful post-downgrade verification includes a connectivity test sourced from the USB adapter’s address, successful DNS, and rndis0 traffic counters—not just successful USB enumeration.

Firmware identification and diagnostic limits

The working firmware is:

e5800-4.8.5_release2-996-0603-1780458650

My retained record of the failing firmware shows glversion = 4.10.0; its full release/build suffix has not yet been recovered. I would appreciate GL.iNet’s help identifying the corresponding OTA build so the correct versions can be compared.

The report includes RNDIS/IPA-related kernel errors from separately labelled capture windows. They are investigation leads, not a complete continuous trace or a proven root-cause explanation.

Support request

I emailed GL.iNet support on 8 September 2026, attaching English and Chinese reports and diagnostic evidence. I am posting here to ask whether anyone has encountered the same problem and to help connect the report with the appropriate E5800 team.

Could the E5800 USB/RNDIS team please investigate this firmware-dependent failure and advise on a 4.10.x fix or official interim patch? Downgrading restores operation on my setup, but I would appreciate a fix in the newer firmware.

If the team cannot reproduce it, the exact firmware build, Windows version, and USB connection used for their test would help us compare environments.

Thank you for any guidance or assistance.

1 Like

Hi,

Thank you for the detailed test information.

We performed a local test with an E5800 running 4.10.0 release5 and a Windows 11 25H2 PC (build 26200.8875).

With a USB-A to USB-C connection, Windows detected the device as Remote NDIS Compatible Device, obtained a 192.168.8.x address, and USB networking worked normally. We were unable to reproduce the Code 10 issue in our current test environment.

  • If convenient, could you please test 4.10.0 again and keep the USB cable connected after Code 10 appears? At that time, please collect the following output via SSH so we can compare the failed attachment with our working test:
cat /etc/glversion
cat /etc/version.type
cat /etc/version.date

ip link show rndis0
bridge link | grep rndis
cat /sys/class/net/rndis0/carrier
cat /sys/class/udc/*/state

dmesg | tail -n 200

The logs in the evidence package already provide several useful RNDIS/IPA observations, but since they were collected from separate windows, a complete capture from a single failed USB connection would help us compare the initialization sequence more accurately.

  • As an additional comparison, could you also try the 10Gbps USB-C to USB-C cable supplied with the Mudi 7 and let us know whether Windows shows the same Code 10 behavior?

Thank you again for your help with the investigation.

Hi @charles2,

Thank you for testing this and providing the working comparison.

I tested again on 4.10.0 release5, and Windows still reports “This device cannot start. (Code 10)” for the Remote NDIS device. I also tried the stock 10 Gbps USB-C-to-USB-C cable supplied with the Mudi 7 and still encountered Code 10.

My Windows 11 workstation runs Windows 11 Enterprise 25H2, build 26200.9168.

I kept the USB cable connected after Code 10 appeared and collected the following SSH output:

BusyBox v1.36.1 (2024-07-15 22:14:18 UTC) built-in shell (ash)

  _______                     ________        __
 |       |.-----.-----.-----.|  |  |  |.----.|  |_
 |   -   ||  _  |  -__|     ||  |  |  ||   _||   _|
 |_______||   __|_____|__|__||________||__|  |____|
          |__| W I R E L E S S   F R E E D O M
 -----------------------------------------------------
 OpenWrt 23.05.4, r24012-d8dd03c46f
 -----------------------------------------------------
root@GL-E5800:~# cat /etc/glversion
4.10.0
root@GL-E5800:~# cat /etc/version.type
release5
root@GL-E5800:~# cat /etc/version.date
2026-08-25 15:09:15
root@GL-E5800:~# 
root@GL-E5800:~# ip link show rndis0
40: rndis0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast master br-lan state DOWN mode DEFAULT group default qlen 1000
    link/ether 42:66:6d:9a:13:98 brd ff:ff:ff:ff:ff:ff
root@GL-E5800:~# bridge link | grep rndis
40: rndis0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 master br-lan state disabled priority 32 cost 100 
root@GL-E5800:~# cat /sys/class/net/rndis0/carrier
0
root@GL-E5800:~# cat /sys/class/udc/*/state
configured
root@GL-E5800:~# 
root@GL-E5800:~# dmesg
[   94.442478][ T8141] ipa-wan ipa3_wwan_set_modem_state:5031 nlmsg: <ALERT_NAME=upstreamEvent> <UPSTREAM=rmnet_data0> <STATE=UP>
[   94.456076][ T8141] ipa-wan ipa3_wwan_set_modem_state:5031 nlmsg: <ALERT_NAME=upstreamEvent> <UPSTREAM=rmnet_data0> <STATE=UP>
[  121.732884][T20661] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONNECTED
[  121.750990][T20664] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONFIGURED
[  121.763014][T20664] [guangwei.li] this script only for rndis and ecm function switch.
[  121.780208][T20664] [guangwei.li] switch to ecm driver.....
[  121.824555][T20700] Switching to composition Quectel
[  121.834708][T20704] Launch adb is starting adbd... 
[  121.849700][T20705] /sbin/adbd is already running
[  122.901612][T20704] Started adbd. 
[  123.927305][T20979] dwc3 a600000.dwc3: request 0000000023b5d819 was not queued to ep4in
[  123.947397][  T122] android_work: sent uevent USB_STATE=DISCONNECTED
[  123.947734][T20979] dwc3 a600000.dwc3: request 0000000064913101 was not queued to ep0out
[  123.984925][   T57] RNDIS_IPA NetDev pipes disconnected (0 outstanding clr)
[  123.996224][ T8141] __ipa_add_flt_get_ep_idx: 4 callbacks suppressed
[  123.996233][ T8141] ipa __ipa_add_flt_get_ep_idx:1262 ep not connected ep_idx=0
[  124.011105][T20984] QCMAP: LINK_DOWN message posted 
[  124.243041][T20979] RNDIS_IPA NetDev queue is stopped
[  124.279597][T21065] QCMAP: Interface Down for rndis0
[  124.320158][T20979] RNDIS_IPA NetDev was cleaned
[  124.390534][T21171] [j_gadget] symlink = f0, target = gsi.ecm, interface_num = 0, interface_count = 2
[  124.402118][T20700] binding UDC with Gadget... a600000.dwc3
[  124.408680][T20700] [j_gadget] assign id 0 to function gsi.ecm
[  124.414899][T20700] [j_gadget] assign id 1 to function gsi.ecm
[  124.421111][T20700] [ecm_mac] guangwei.li only change mac vendor address [5c:4d:bf:29:d1:26]
[  124.428490][T20700] ecm_ipa@ecm_ipa_init@422@ctx:Quectel_ECM: ECM_IPA was initialized successfully
[  124.470743][ T9475] br-lan: port 4(ecm0) entered blocking state
[  124.473471][T21206] QCMAP: Interface Up for ecm0
[  124.480078][T20700] dwc3 a600000.dwc3: Set IRQ thread:irq/157-dwc3 pid:21196 to SCHED_NORMAL prio
[  124.483010][ T9475] br-lan: port 4(ecm0) entered disabled state
[  124.495046][T20664] [guangwei.li] switch to ecm driver done
[  124.500504][ T9475] device ecm0 entered promiscuous mode
[  124.521894][   T21] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  124.529729][T21237] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONFIGURED
[  124.536386][T21246] QCMAP: HW Address for dev ecm0: e6:eb:c9:7a:36:cb
[  124.548830][T21237] [guangwei.li] this script only for rndis and ecm function switch.
[  124.619049][T21322] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=DISCONNECTED
[  124.648708][   T21] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  124.770718][   T21] android_work: sent uevent USB_STATE=CONNECTED
[  124.779981][   T21] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  124.788673][   T21] android_work: sent uevent USB_STATE=CONFIGURED
[  124.795261][ T8416] dwc3 a600000.dwc3: Clr_TRB ring of ep1in
[  124.801704][ T8416] dwc3 a600000.dwc3: Clr_TRB ring of ep1out
[  124.813441][   T40] IPv6: ADDRCONF(NETDEV_CHANGE): ecm0: link becomes ready
[  124.820361][ T8416] ipa_usb_notify_cb: Set net_ready_trigger
[  124.820675][ T8416] ecm_ipa@ecm_ipa_connect@585@ctx:kworker/u8:4: ECM_IPA was connected successfully
[  124.821810][   T40] br-lan: port 4(ecm0) entered blocking state
[  124.842283][   T40] br-lan: port 4(ecm0) entered forwarding state
[  124.852671][ T9475] device ecm0 left promiscuous mode
[  124.863519][ T9475] br-lan: port 4(ecm0) entered disabled state
[  124.905439][T21484] QCAMP: ecm0 mode
[  124.922835][T21497] QCMAP: LINK_UP message posted 
[  125.049787][T21608] QCMAP: Interface Down for ecm0
[  125.091933][T21635] QCMAP: LINK_DOWN message posted 
[  125.105025][T21658] QCMAP: Interface Up for ecm0
[  125.138342][T21695] QCAMP: ecm0 mode
[  125.155374][T21708] QCMAP: LINK_UP message posted 
[  135.708949][T24902] conntrack (24902) used greatest stack depth: 8656 bytes left
[  147.326043][T27415] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONNECTED
[  147.345932][T27418] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONFIGURED
[  147.358260][T27418] [guangwei.li] this script only for rndis and ecm function switch.
[  152.335681][T28625] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=DISCONNECTED
[  166.347747][ T9475] br-lan: port 4(ecm0) entered blocking state
[  166.353931][ T9475] br-lan: port 4(ecm0) entered disabled state
[  166.366181][ T9475] device ecm0 entered promiscuous mode
[  166.376997][ T9475] br-lan: port 4(ecm0) entered blocking state
[  166.383163][ T9475] br-lan: port 4(ecm0) entered forwarding state
[  166.421841][T31502] QCMAP: HW Address for dev ecm0: e6:eb:c9:7a:36:cb
[  168.783252][T31947] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONNECTED
[  168.802483][T31950] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONFIGURED
[  168.814573][T31950] [guangwei.li] this script only for rndis and ecm function switch.
[  263.333106][   T40] br-lan: port 4(ecm0) entered disabled state
[  263.335276][T13611] ecm_ipa@ecm_ipa_disconnect@886@ctx:kworker/u8:5: ECM_IPA was disconnected successfully
[  263.350126][  T384] QCMAP: LINK_DOWN message posted 
[  263.364603][ T2668] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  263.384091][ T8141] ipa __ipa_add_flt_get_ep_idx:1262 ep not connected ep_idx=0
[  263.487226][ T2668] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  263.495077][ T2668] android_work: sent uevent USB_STATE=CONFIGURED
[  263.504747][  T437] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONFIGURED
[  263.516914][  T437] [guangwei.li] this script only for rndis and ecm function switch.
[  263.531900][  T437] [guangwei.li] switch to rndis driver.....
[  263.572910][  T477] Switching to composition Quectel
[  263.584286][  T481] Launch adb is starting adbd... 
[  263.599324][  T482] /sbin/adbd is already running
[  264.665254][  T481] Started adbd. 
[  265.695908][   T88] android_work: sent uevent USB_STATE=DISCONNECTED
[  265.706270][  T503] ecm_ipa@ecm_ipa_stop@807@ctx:rm: can't do network interface down without up
[  265.720028][  T503] br-lan: port 4(ecm0) entered disabled state
[  265.727894][  T506] QCMAP: Interface Down for ecm0
[  265.734883][  T503] device ecm0 left promiscuous mode
[  265.742202][  T503] br-lan: port 4(ecm0) entered disabled state
[  265.798808][  T503] ecm_ipa@ecm_ipa_cleanup@942@ctx:rm: ECM_IPA was destroyed successfully
[  265.861084][  T602] [j_gadget] symlink = f2, target = ffs.diag, interface_num = 2, interface_count = 1
[  265.872803][  T610] [j_gadget] symlink = f3, target = gser.0, interface_num = 3, interface_count = 1
[  265.885118][  T617] [j_gadget] symlink = f4, target = cser.dun.0, interface_num = 4, interface_count = 1
[  265.902884][  T636] [j_gadget] symlink = f5, target = cser.dun.2, interface_num = 5, interface_count = 1
[  265.919304][  T654] [j_gadget] symlink = f0, target = gsi.rndis, interface_num = 0, interface_count = 2
[  265.931724][  T477] binding UDC with Gadget... a600000.dwc3
[  265.938067][  T477] [j_gadget] assign id 0 to function gsi.rndis
[  265.944687][  T477] [j_gadget] assign id 1 to function gsi.rndis
[  265.970327][  T477] RNDIS_IPA NetDev was initialized
[  265.976333][  T477] [j_gadget] assign id 2 to function ffs.diag
[  265.983217][  T477] [j_gadget] assign id 3 to function gser.0
[  265.987414][ T9475] RNDIS_IPA NetDev was opened
[  265.989463][  T477] [j_gadget] assign id 4 to function cser.dun.0
[  266.003058][  T700] QCMAP: Interface Up for rndis0
[  266.007946][  T477] [j_gadget] assign id 5 to function cser.dun.2
[  266.041768][  T477] dwc3 a600000.dwc3: Set IRQ thread:irq/157-dwc3 pid:709 to SCHED_NORMAL prio
[  266.054787][  T437] [guangwei.li] switch to rndis driver done
[  266.065783][ T2668] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  266.088648][  T720] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=DISCONNECTED
[  266.193215][ T2668] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  266.315566][ T2668] android_work: sent uevent USB_STATE=CONNECTED
[  266.327019][ T2668] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  266.336023][  T709] [rnids_mac] RNDIS_OID_802_3_PERMANENT_ADDRESS 18:3f:55:3f:3e:1b
[  266.344493][ T8416] IPv6: ADDRCONF(NETDEV_CHANGE): rndis0: link becomes ready
[  266.345457][ T2668] android_work: sent uevent USB_STATE=CONFIGURED
[  266.352566][T28543] dwc3 a600000.dwc3: Clr_TRB ring of ep1in
[  266.366289][T28543] dwc3 a600000.dwc3: Clr_TRB ring of ep1out
[  266.369725][   T88] rndis_ipa_start_xmit: 5484 callbacks suppressed
[  266.369736][   T88] RNDIS_IPA@rndis_ipa_start_xmit@1040@ctx:kworker/2:2: Missing pipe connected and/or iface up
[  266.382409][T28543] ipa_usb_notify_cb: Set net_ready_trigger
[  266.389185][T28543] RNDIS_IPA NetDev pipes were connected
[  266.392854][  T808] QCAMP: rndis0 mode
[  266.410258][  T820] QCMAP: LINK_UP message posted 
[  269.487086][  T709] dwc3 a600000.dwc3: request 0000000090d8afe1 was not queued to ep4in
[  269.504559][ T2668] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  269.517361][T13611] RNDIS_IPA NetDev pipes disconnected (0 outstanding clr)
[  269.523667][ T2035] QCMAP: LINK_DOWN message posted 
[  269.526362][T13611] ipa_work_handler: skip disable, channels already released
[  269.542379][ T8141] ipa __ipa_add_flt_get_ep_idx:1262 ep not connected ep_idx=0
[  269.610731][ T2668] msm_eusb2_phy ff4000.hsphy: Could not get usb psy
[  269.619578][ T2668] android_work: sent uevent USB_STATE=CONFIGURED
[  283.916550][ T9475] br-lan: port 4(rndis0) entered blocking state
[  283.922874][ T9475] br-lan: port 4(rndis0) entered disabled state
[  283.930165][ T9475] device rndis0 entered promiscuous mode
[  283.965815][ T5998] QCMAP: HW Address for dev rndis0: 42:66:6d:9a:13:98
[  286.310352][ T6442] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONNECTED
[  286.330375][ T6445] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONFIGURED
[  286.342953][ T6445] [guangwei.li] this script only for rndis and ecm function switch.
[  286.380971][ T6457] [guangwei.li] recv uevent ACTION=change SUBSYSTEM=android_usb USB_STATE=CONFIGURED
[  286.393663][ T6457] [guangwei.li] this script only for rndis and ecm function switch.
root@GL-E5800:~# 

dmesg_full.txt (124.9 KB)

Could you please compare this with your working release5 test?

Thank you again for your assistance.

Hi,

Thank you for providing the additional test results and logs.

From the information collected, the USB device reaches the configured state, while rndis0 remains NO-CARRIER with carrier = 0. The log also shows the RNDIS/IPA connection being established and subsequently disconnected.

We will continue trying to reproduce the issue in our test environment and work with the relevant team to further analyze and investigate it. If there are new findings or updates, we will share them with you here.

Thank you for your understanding and support.