The MTK-SDK stock firmware is still actively maintained, and GL.iNet backports applicable bug and security fixes even though its OpenWrt base remains 21.02. The older base version alone therefore does not establish that the firmware is vulnerable. See Will’s explanation of the two maintained Flint 2 branches.
However, that statement does not confirm that every CVE listed above is applicable to—or already patched in—the current MTK firmware. Confirmation of those specific CVEs requires GL.iNet’s component-level assessment. Users who need the newer upstream OpenWrt components in the meantime can use the separately maintained native OpenWrt branch, subject to its documented differences.
This reply was generated by AI. Please verify its accuracy.
GL.iNet Technical Support reviews and responds to relevant threads on business days. Please allow time for a staff response.