No updates for many models. What about security?

OpenWrt and all other serious software fix security vulnerabilities at least every few months, sometimes even faster.

But many GL-iNet models that are still officially supported have not received an update for more than a year (EG: Puli, Spitz, Shadow, Beryl, Mango, Marble, Slate Plus, Spitz Plus, Brume2, Mudi).

This is not good and especially now with AI finding vulnerabilities and many GL-iNet model using very old OpenWrt version. It feels these routers are not secure.

4 Likes

nope... most SOHO routers for general consumers are not that often updated if not at all with some vendors, Asus as a example got exposed about this not so long ago, and if you look on the OpenWrt forums you can find all kinds of interesting topics how support is added and what type of OEM software runs on it, which is also a old modified version of OpenWrt from Mediatek or Qualcomm as SDK.

While this can be true, you still need to understand companies are free to backport patches from these vulnerabilities to older firmware, so this means you need to trust the vendor on their word, from my own experience if I compare it with things like tp-link I'm happy with GL-iNet.

most other brands also have not every vulnerability patched... even if they tried to lock it down with signed firmware.

Some vulnerabilities are less severe than that they sound, of course it is better if they get patched anyway, but purely aimed here, there is no difference in a other soho brand and sometimes they are more bad, most get blocked thanks by the firewall and are local based vulnerabilities, this only becomes dangerous if you attempt to do non SOHO things on it like docker or some other virtualizations, with the exception of luci and nginx I think these 2 can be a severe one when someone has it's target to write local malware, unfortunately some APT groups has their eyes in writing malware for specific routers, but luci and nginx are not so hard to backport compared to kernel based things, you could in theory also just remove the whole web part and then it becomes alot harder for them, like how the firewall guest rule blocks the ui that is one example to work around it if a device is suspicious.

it gets only more severe if the vulnerability in question can be archieved remotely.

GL-iNet uses Mediatek SDK, and Qualcomn SDK these are chipvendor specific sdk kits with a older version of OpenWrt, this includes private drivers for wireless which are propetairy and not in vanilla OpenWrt, vendors like GL-iNet choose rather older versions because that is what works the most stable without spontaneous changes or very breaking ones, for production this makes perfect sense.

The Opal received firmware 4.8.3 and the Beryl 7 got 4.90 this month. Both came with many new features and security fixes.

The routers that @gladly listed have not seen an update in over a year, and models like the Slate Plus and the Shadow are still being sold even though they are stuck on firmware 4.5.22 and 4.3.27 respectively, both with known security bugs.

The fact that GL iNet stops releasing firmware for some models but continues to sell and profit from them is just pathetic.

3 Likes

But the business has to weigh up the cost of developing and patching those devices versus the return on investment costs, it might not make sense to GL-iNet to invest in patching those products as they are end of life, and may just release a fix patch once inventory is sold out and they’ve recouped costs.

1 Like

This is kind of my thought to.

But we need to be careful about this before they EOL devices with no reason to EOL.

I think some of these routers which don't get much updates are often those with a really small space, or they come with some very specific driver which takes up space or does not work well with newer userland or kernel packages like those with a mobile modem as driver.

I have my suspicion if I look to the Beryl 7 this one has a chance to maybe EOL much earlier than what I had initially thought but the memory usage is high because of the wifi 7 driver, so in this case the ram can be a very limited factor, for slate plus I don't know if something similar lingers.

Does GL-iNet want to be like them or does it want to have good security? Good browsers and operating systems are updated at least every month, and some other software every quarter. But if you want to compare to good router updating, the most important comparison is OpenWrt which GL-iNet uses.

In the past year, while the routers I listed recevied zero updates from GL-iNet, OpenWrt was updated in June 2025, September 2025, October 2025, December 2025, March 2026, May 2026, May 2026 (another in the same month) and July 2026. Many many security vulnerabilities were fixed in OpenWrt, the kernel and in other components.

I doubt that older versions of OpenWrt and the GL-iNet additions don’t have many security vulnerabilities. Every software does. The important thing is to update and fix all the time. Especially now with AI.

2 Likes

I cannot awnser that because I do not speak as a GL-iNet representative, but for them this is not pratical in a stance of a business to keep up with OpenWrt, so I do compare them as any other vendor.

Although in my eyes this is also not OpenWrt but marketing, with a little bit of freedom you see with OpenWrt with luci.

It is a off shoot of OpenWrt but basically it is just Mediatek SDK or a different vendor sdk.

It is something I find they fail at because many people want the expectation to be full OpenWrt and updated.

In case someone had his firmware update set to beta - set it to stable or you will never receive the update. I was stuck on all my routers - Flint-2, Flint-3 and Slate-7 to some old version because I was waiting for beta releases. Download betas directly from the web and upload to the router.