OpenWRT 25.12.5 - fixes huge number of CVE's - Flint2 still on 24.10.4

Flint 2 OP24-4.9.0 is looking very old and risky given this:

Security fixes

This release fixes several remotely triggerable vulnerabilities in
core network services that are enabled by default. Updating is strongly
recommended.

Beyond the issues listed above, this release fixes a number of
further security problems for which no CVE number or dedicated advisory
was assigned. We strongly recommend upgrading

That’s an enormous number of vulnerabilities that GL-inet Flint 2 potentially exposes its users to.

When will Flint 2 get an update that is actually up to date with 25.12.5?

5 Likes

Hi

Thank you for bringing this to our attention.

The Flint 2 OP25 firmware is currently in the final stages of development. Assuming testing goes smoothly and we don't discover any major issues that would significantly impact usability, it should be ready for release soon.

5 Likes

Excellent.

Will it resolve all those CVE’s fixed in 25-12.5?

It should be 25.12.5, so the CVE vulnerability will be fixed just like the upstream version.

4 Likes

That’s good news, Will.

I really like GL-inet’s user interface.

Combined with the latest openwrt security fixes makes it a really great product.

What will the WiFi power levels be like compared to OP24? I read people saying the 4.9.0 releases were much weaker.

Will this release work with the Android app / parental controls. I note the May 2026 version still hasn’t resolved the issue with trying to update the schedules.

Will these security fixes be made available to other models such as the Beryl AX soon? These are some very important CVE’s to patch.

1 Like

Hi

Our development team is currently evaluating whether other models are affected and whether they also require a fix. This may take some additional time.

We'll let you know if we have any updates.

Hi Will,

Could you please review the issues found so far in OP25-4.9.1, as discussed in the other OP25 thread?

Cheers

Hi

We'll look into it.

2 Likes

Hey will, are these fixes being backported to the closed source MTK firmware (based on 21.02)? Or is that firmware decidedly unsafe in the face of these CVEs (and many others presumably between 21.02 and 24.10.4)

The MTK-SDK stock firmware is still actively maintained, and GL.iNet backports applicable bug and security fixes even though its OpenWrt base remains 21.02. The older base version alone therefore does not establish that the firmware is vulnerable. See Will’s explanation of the two maintained Flint 2 branches.

However, that statement does not confirm that every CVE listed above is applicable to—or already patched in—the current MTK firmware. Confirmation of those specific CVEs requires GL.iNet’s component-level assessment. Users who need the newer upstream OpenWrt components in the meantime can use the separately maintained native OpenWrt branch, subject to its documented differences.

This reply was generated by AI. Please verify its accuracy.

GL.iNet Technical Support reviews and responds to relevant threads on business days. Please allow time for a staff response.