|
|
Asuswrt-Merlin 388/NG Changelog
===============================
3004.388.12 (xx-xxx-2026)
- NOTE: There has been important changes to OpenVPN, some necessary with the update to OpenVPN 2.7. Make sure you read the details below, especially if running an OpenVPN server with deprecated features that have now been removed.
- NEW: Added tls-crypt V2 authentication support to OpenVPN servers. Don't forget to generate a client key for each client that will connect to you. The keys can be generated from the webui, after you have started the server with TLS control set to "Encrypt Channel V2". A new button will appear that can generate a new client key each time you click on it.
- UPDATED: Merged with GPL 388_25633.
- UPDATED: dnsmasq to 2.93 + some backports.
- UPDATED: OpenVPN to 2.7.5.
- UPDATED: tor to 0.4.8.22.
- UPDATED: curl to 8.17 (backport from 102_39848).
- UPDATED: wget to 1.25 (backport from 102_39848).
- UPDATED: dropbear to 2026.92.
- UPDATED: miniupnpd to 2.3.10-42965d7.
- UPDATED: haveged to 1.9.22.
- CHANGED: Added new 2024 DNSSEC trust anchor, which will start being used in October 2026.
- CHANGED: VPN Status page can now detect running but non-connected WireGuard client tunnels, and report them as being in an error state.
- CHANGED: Include two separate miniupnpd builds - with, and without IGDv2 support. Run the appropriate version based on whether the user enables IGDv2 or not. This is to improve compatibility, as IGDv2 support is still problematic for some clients, and cannot be fully disabled at run time.
- CHANGED: dhcpc-event script will now be run after the event occured rather than before, allowing it to modify what was applied to the router configuration.
- FIXED: Multiple minor CVE for OpenSSL 1.1: CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-42766 and CVE-2026-45447 (backports by RSDNTWK)
- FIXED: Starting a client through VPNDirector would fail to update routing rules.
- FIXED: Security issue on the Site Survey page (reported by Sasha Romijn).
- FIXED: UPnP port forwards not working if port forwarding or NAT weren't already enabled (patch from Asus)
- FIXED: hostname missing from hosts file (regression from GPL merge)
- FIXED: ntpd stops answering after a few days (workaround by restarting it every 24 hours)
- FIXED: Option to show/hide DHCP events was missing.
- REMOVED: Support for secret static key authentication from both OpenVPN clients and servers. Deprecated since 2.7.0, and considered outdated in terms of security.
- REMOVED: Compression support from OpenVPN server. Update your client configs if you were using it. Client support is still available for backward compatibility with old remote server setups, but expect it to be removed from OpenVPN 2.8. If for some reason you absolutely need it for your server (despite the security implications), you can still enable it through the Custom settings.
- REMOVED: Some obsolete/non-working OpenVPN settings such as fast-io (no longer working with 2.7) or data cipher (were replaced with NCP a few years ago).

更新机型
* GT-AX11000
* GT-AXE11000
* RT-AX58U
* RT-AX68U
* RT-AX86U
* RT-AX88U

下载链接: https://pan.baidu.com/s/13oLYVLMkGt3HNt6bBwHX1w
提取码:
|
|