Critical Security & Kernel Update: Linux 5.15.192 Patches CVE-2025-38352, Plus Modem & Network Fixes
New Feature
- Tcpdump Update
#653238, Tcpdump has been updated to version 4.99.4. - Modem changes
#658041, Attaching to the IMS (IP Multimedia Subsystem) is disabled per default for Telit data modems (LN920,FN980 and FN990) but this can be enabled using the config parameter "modem.X.ims.telit.status=1" per each modem installed. Some network providers (MNO) require IMS to be able to use SMS. Please be aware that enabling the IMS function may lead to communication issues or connection interruptions, depending on your mobile network provider’s (MNO) compatibility and configuration. - Web-UI Error Messages Improvements
#658042, If the software update of a signed image fails, we now print a more useful error message that can help to identify the cause of the failure
Security Fixes
- CVE-2025-38352
#658046 CVE-2025-38352 fixes Linux kernel CPU timer concurrency issues. Kernel updated to version 5.15.192
Fixes
- Firewall fixes
#531061, There now exists a firewall rule, that allows processes to communicate to other processes via the loopback interface. This resolves an issue where certain daemons were not functioning correctly. - Config status fixes
#615248, When issuing the cli command ’cli status -s’, the parameter CONFIG_MODIFIED showed a wrong time. Now it is fixed. - DDNS fixes
#649894, A issue that prevented the ’Use outgoing interface address’ option of the ’Dynamic Address’ parameter from working has been fixed. - PPPoE fixes
#655849, A bug has been fixed where an online PPPoE WAN interface would not set a default route - NB1601 SIM switch
#657977, Under certain circumstances, when two SIM cards are inserted in the NB1601, changing the SIM card via the software might not have work. This issue has been fixed
Known Issues
- WAN-MTU
#578728, If the cellular network does not provide MTU information, ublox LARA-L6 modems use 1428 Byte as a default. This may lead to issues if an MTU of 1500 is expected. - OpenVPN issues
#630573, When using OpenVPN tunnel in expert client mode disabling the setting " Apply network settings pushed by OpenVPN server" will require a router reboot to apply correctly. - WWAN connection MTU issue
#639705, When manually setting an MTU value smaller than the MTU used by the mobile network carrier for a router with a uBlox TOBY-L2 modem, the router will reboot if it receives packets with a larger-than-configured MTU size from the mobile connection. Do not configure MTU sizes smaller than what the mobile network carrier specifies. - Config options breaks GNSS functionality
#643066, The legacy config option gpsd.0.ftimeout will break GNSS functionality and NMEA stream if set to "1" via CLI. - SNMP Bug
#646394, On NB1810 devices SNMP GET stops working after enabling & configuring LAN2 as WAN. Disabling LAN2 will not make SNMP GET work again. A reboot will be required to rectify the issue. - Downgrade warning
#670564, Starting with NRSW 5.0.0.100 we only support signed Software images. Therefore a downgrade to NRSW Releases 4.9 and earlier is not possible. - Dnsmasq error in combination with hotspot on vlan
#670580, Analysis shows that a router can reboot if you have a hotspot running on a routed VLAN interface due to a watchdog reboot of the dnsmasq process. Please contact support for a workaround. - WLAN mesh point
#670584, The mesh point functionality of WLAN does not work on NB160

