GL.iNet Firmware Mirror

Community backup archive of Stable, Beta, Legacy & Factory firmware builds for GL.iNet routers, KVM and IoT devices

Includes firmware releases from Jan 2023 onward, plus Legacy 3.x builds for older models.
Mirrored file checksums are automatically verified against corresponding files published on dl.gl-inet.com

Provided and maintained by RemoteToHome Consulting RTH provides specialized security consulting for remote work and location privacy using VPN & KVM solutions.

Routers

KVM over IP

IoT

Router Firmware

GL-A1300 Slate Plus a1300

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.5.22 2025-04-08
SHA256: ef25c2803d1b0e72... SHA256: 08ce571259dc5cd9... 🔗 share
Release notes

V4.5.22

Overview

This version fixed some security vulnerabilities.

4.5.19 2024-08-26
SHA256: e02146ca193eea8c... SHA256: c87b6c459f0f90ab... 🔗 share
Release notes

V4.5.19

Overview

This version fixes some security vulnerabilities.

Supported Models

GL-X300B Collie, GL-A1300 Slate Plus, GL-B3000 Marble.

4.5.17 2024-06-20
SHA256: 1dbfddd374350a70... SHA256: 01887be23c3d05b0... 🔗 share
Release notes

V4.5.17

Overview

This firmware release provides fixes to various bugs and security vulnerabilities.

Supported Models

GL-X300B Collie, GL-A1300 Slate Plus.

Bug fixes

  • Fixed an issue where relaying 5GHz Wi-Fi using 165 channels would fail and cause the repeater to abnormally.
4.5.16 2024-03-21
SHA256: b288fb6a6940aa03... SHA256: 41090f62103802be... 🔗 share
Release notes

V4.5.16

Overview

This firmware release provides fixes to some bugs and security vulnerabilities.

Supported Models

GL-A1300 Slate Plus, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-MT3000 Beryl AX, GL-MT2500/GL-MT2500A Brume 2

Improvements

  • Optimized the client IP assignment policy in TAP-S2S mode when the device subnets of OpenVPN Client and OpenVPN Server were the same.
  • Upgraded Tailscale to version 1.58.2.

Bug fixes

  • Fixed an issue where multiple parsed AllowedIPs were incorrect when parsing the uploaded WireGuard client configuration files.
  • Fixed an IP conflict issue that occured when adding a client profile to WireGuard after modifying the PeerIP of the WireGuard server configuration via SSH.
  • Fixed an issue where the router’s Tailscale service data would be forwarded through a VPN tunnel when the VPN Client global mode was enabled.
  • Fixed an issue where inbound data from non-VPN interfaces would not trigger port forwarding rules when VPN was enabled.
  • Fixed an issue where some devices from the TAP-S2S OpenVPN client would not display properly on the client page.
  • Fixed an issue where the OpenVPN server certificate may be lost after rebooting the device.
  • Fixed an issue where the address’s description field was lost after upgrading to firmware v4.5.0 from v4.4.x when the user chose to keep router settings.
  • Fixed an issue where selecting manual mode on the MAC address page and entering the factory default MAC address on the ethernet page would result in an unsuccessful configuration even after connecting to the repeater successfully at first.
  • Fixed an issue where the network speed limit feature was still activated after enabling network speed limit, enabling network acceleration, and rebooting the device.
  • Fixed some known vulnerabilities.
4.5.0 2024-02-01
SHA256: b23df6e13961dfa7... SHA256: 252282754fd60e85... 🔗 share
Release notes

V4.5.0

Overview

This release version mainly enhances network security and fixes known issues with network status detection, providing users with the option to manually add languages in the language community and the option to pre-emptively experience the new version. It is compatible with Full Cone NAT and SIP ALG features found in other routers. Optimization, bug fixing, and vulnerability repair for more vendors are shown below.

This release is available for the following models:
GL-A1300 Slate Plus
GL-AX1800 Flint
GL-AXT1800 Slate AX
GL-MT3000 Beryl AX
GL-MT2500/GL-MT2500A Brume 2
GL-X300B Collie

New features

  • Reconstructed mwan3 and renamed it as kmwan. Optimized failover and load balancing, as well as network status in various scenarios.
  • Added the Security configuration page.
  • Added grayscale testing design. Added RC version subscription and upgrade.
  • Added the communityization of language packs to support manual addition.
  • Added support for IPoE, and support for configuring VLAN ID during DHCP and static dialing.
  • Added Full Cone NAT function.
  • Added the SIP ALG option.
  • Added new temperature protection setting for MTK Wi-Fi.

Improvements

  • Optimized the side route UI interaction and add the option to turn off the DHCP server itself.
  • Optimized the restart process of the relay program.
  • [Only for GL-X300B Collie] Optimized the functionality of RS485, the UI, and localization.
  • Optimized the Tailscale mechanism.
  • Updated language files and pull translation scripts.

Bug fixes

  • Fixed an issue where the interface jumped due to the incorrect change in the client's online time.
  • Fixed an issue with the TTL settings not taking effect.
  • Fixed an issue where scanning always indicated that it was in DFS when all interfaces were disabled.
  • Fixed an issue of failing to enable Wi-Fi for the first time after upgrading.
  • Fixed an issue of failing to connect to the AP due to a failure to parse IE_HT_CAP.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.4.6 2023-09-08
SHA256: 6f39cfd104ef31d2... SHA256: 75e184c1574ad20e... 🔗 share
Release notes

V4.4.6 - Sep 8,2023

VPN

  • Fixed the problem that the OpenVPN client cannot access the Internet after dialing up, either by rebooting the router or by restarting the feature.

WireGuard

  • Fixed the problem that WireGuard client gets error 'Error: inet6 prefix is expected rather than' when connecting to server.
  • Fixed the problem that the WireGuard client of the device under test does not disconnect after the WireGuard server of the device accompanying the test is shut down, and keeps showing the connection status.

Repeater

  • Fixed the problem that the wireless network connection is abnormal after the router repeater DFS channel.

Tailscale

  • Fixed the problem that when using PPPoE dialup, the Internet cannot be accessed when tailscale is enabled.
  • Fixed the problem that the Good Cloud platform fails to connect when Tailscale is enabled.

Clients

  • Fixed the problem that the black/white list function is not compatible with the old version of blacklist.

Upgrade

  • Fixed the problem that online upgrade reports error '-4,fetch firmware name fail: network unreachable'.

DDNS

  • Fixed the problem that all TCP ports are opened when DDNS is enabled to allow http/https access in reserved configurations.

LAN

  • Fixed the problem that br-lan occasionally hangs when changing LAN IP.
4.4.5 2023-08-11
SHA256: 79c4e63c40c2053a... SHA256: 675c149df383e907... 🔗 share
Release notes

V4.4.5 - Aug 11,2023

VPN

  • Open VPN server when using tor,delete -4VPN conflict prompt.

GoodCloud

  • Fix MQTT runs abnormally after obtaining 4G/5G information.

Modem

  • Fix M2 demo board cannot recognize SIM card.
  • Fix abnormal display of LTE bandwidth.

Tailscale

  • Add support for accepting routes option.
  • Add support for mutual access between Tailscale subnets.

Dns

  • Fix next-dns setting does not take effect.

WireGuard

  • Fix WireGuard cannot reconnect after working for two days.

Parental Control

  • Fix adding specified url does not take effect.
4.2.3 2023-07-06
SHA256: b5076312d0e8aa9e... SHA256: 03b963370a36a96f... 🔗 share
Release notes

Bug Fixes

Fixed the problem that after the MT3000 relays the 160M Hz hotspot, the AP becomes 20M.
Fixed the problem that the AX/AXT1800 cannot access the AP itself after relaying the DFS 140 channel.
Fixed the problem that parental control cannot block blacklist websites in newer browsers.
Fixed the externder working mode, the superior cannot ping the subordinate.
Fixed the problem that openvpn port forwarding fails after the reserved configuration is upgraded.
Fix the problem that mqtt cannot report SSID.
Fixed the problem that ddns occasional interface return error.
Fixed The relay cannot connect to Huawei TC7102 160MHz 5GWiFi.
Fix single sim card slot does not return dual sim card slot information.
Fixed the problem that after the adguardhome function is turned on on the A1300 and the adguardhome is turned off, the visitor has no network.
Fixed the problem that Openvpn Server and wireguard Server shut down remote access to the LAN subnet, but the Openvpn and wireguard clients can still access the IP address of the PC on the LAN side of the server.
Fixed the AP bridge mode, the bridge is not successful. The address assigned by the superior cannot be obtained.
Support-EM160R-EM060K-EM120K-RM520N-modem.
Fixed the problem that A1300 cannot recognize USB3.0 external modem.
Fixed the problem of abnormal equipment caused by the time zone or 160M bandwidth issued by the GoodCloud.
Correct the display problem of the LED light in the unconnected network mode.
Fixed the problem of unsuccessful dialing using external modem, QMI and QCM protocol dialing.
Roll back MTK SDK from v7.6.7.0 to v7.6.6.1.

4.2.1 2023-04-14
SHA256: bd3034300fc9b1ea... SHA256: ee19d727a315a5dd... 🔗 share
Release notes

Bug Fixes

Fixed a problem where the WiFi configuration page showed unavailable channel options.
Fixed a problem where NordVPN could not resolve DNS after keeping settings upgrade.
Fixed a problem where GL-MT3000 failed to recognize USB3.0 modem.
Fixed a problem where the IPV6 rate limiting does not take effect.
Fixed a problem where GL-MT3000 failed to repeat to iPhone 13 and TP-LINK ACR700.
Fixed a memory leak problem in GL-MT3000 when using QCM protocol.
Fixed a probabilistic issue where GL-MT3000 could not apply OpenVPN username and password.
Fixed switch button not taking effect when parental control is enabled on GL-A1300.
Fixed a BUG where clients could not access the internet after failover.

Optimizations

Disabled nginx access logs.
Optimized the MWAN3 online detection threshold.
Optimized the synchronization of configuration files in abnormal situations.
Optimized the repeater scan time of GL-MT3000.

Software Upgrade

Upgraded AdguardHome to V0.107.26.

4.2.0 2023-03-09
SHA256: 1e58be2968165232... SHA256: cb43dc0b62996854... 🔗 share
Release notes

Optimization

Improved IPv6 LAN Mode options. Separates the native and passthrough modes.
Improved the results and hints of the DDNS test.
Improved drop-in gateway feature with DHCP-based solution to increase stability.
Improved LED lighting logic to ensure consistency with the UI.
Improved interaction for MAC address cloning.
Improved networking status alerts in Internet page.
Improved interface tracking settings description for Multi-WAN.
Improved login page with automatic focus to password input box.
Improved VPN client configuration file view with files sorted by name.
Improved the switch name in the VPN global options for whether the GL.iNet service uses VPN or not.
Improved the interaction of set read-only users to read-write users in network storage.
Improved ADGuard Home feature to support seeing which client the request is coming from.

Language

Added German language.

New feature

Added Parental Control feature.
Added Zerotier feature.
Added Tailscale feature.
Added Clear Traffic Statistics button for in client page.
Added DHCP Gateway option for LAN.
Added SSID Visibility option for guest Wi-Fi.
Added support for GoodCloud alerts when new clients join.
Added support for comments for domain and IP profiles in VPN policy.

4.7.2 2024-12-27
SHA256: a40ec11f63a3648d... SHA256: b4f1e3db79ecad9f... 🔗 share
Release notes

V4.7.2

Overview

This version introduces several new features and enhancements that improve the interface interaction for overall user experience.

Support Models

Slate Plus (GL-A1300), Marble (GL-B3000), Collie (GL-X300B).

New Features

  • Added device initialization wizard, including administrator and WiFi password, networking, VPN and other core function settings.
    • Added the Cloud account login function, supporting device binding to the cloud from the firmware web page.
  • Added Domain Name List Subscription function, support VPN policy and parental control to subscribe to online domain name or IP list via URL.
  • Added support for Control D DNS.
  • Added the AP Isolation function.
  • Added the Luci Access Restriction function.
  • Added the Network Port Management page, supporting scheduled and restart of automatic Ethernet MAC updates, WAN/LAN port switching, and displaying network port negotiation rates.
  • Added NordVPN, PIA, Surfshark, Hideme, IPVanish WireGuard VPN, and support AzireVPN registration function.

Optimization

  • Optimized the process for manually adding the WireGuard client configuration file and supporting automatic key generation.
  • Optimized the process for configuring vendor profiles for VPN clients.
  • Optimized Repeater random MAC setting, supporting scheduled and restart of automatic Repeater MAC updates.
  • Optimized the flow of Multi-WAN load network status detection.
  • Optimized OpenVPN Client functionality to allow modification of configuration file names.
  • Optimized page names in the web Administration Panel so that the router is host name appears in the browser tab.
  • Optimized page interactions such as interface error messages and inputable drop-down list designs.
  • Upgraded AdGuard Home to version 0.107.52.
  • Upgraded Tor to version 0.4.8.9.

GL-AP1300 Cirrus ap1300

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.18 2024-08-29
SHA256: f4fd3a7a07dc3df2... SHA256: a4084215c11d9d69... 🔗 share
Release notes

V4.3.18

Overview

This version fixes some security vulnerabilities.

Supported models

Slate (GL-AR750S), Creta (GL-AR750), Mudi (GL-E750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300).

3.218 2024-07-26
SHA256: c50c61c2bd3c6fa8... 🔗 share
Release notes

V3.218

Overview

This firmware release provides fixes to various bugs and security vulnerabilities.

Supported Models

Convexa-S (GL-S1300), Cirrus (GL-AP1300).

Bug fixes

  • Fixed an issue that the client device of the router could not get an IP address if the router as a VPN client disconnects and reconnects with an OpenVPN server in S2S-TAP mode.
3.217 2023-05-08
SHA256: df49296f935e0813... 🔗 share

GL-AR150 White ar150

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
3.216 2023-03-21
SHA256: 6febbdcf75e4ca71... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

GL-AR300M Shadow ar300m

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.25 2025-03-31
SHA256: 30d565360cedebd1... SHA256: 8e528e385678bacc... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.18 2024-08-23
SHA256: dedf06662c5b5f67... SHA256: cbea224daefc6084... 🔗 share
Release notes

V4.3.18

Overview

This version fixes some security vulnerabilities.

Supported models

Slate (GL-AR750S), Creta (GL-AR750), Mudi (GL-E750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300).

4.3.17 2024-06-07
SHA256: 027d27a479fc9cb6... SHA256: cd698560ccbb0edd... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.11 2024-03-20
SHA256: fdfe8a2fea5ed3ca... SHA256: bacfdad3a082d299... 🔗 share
Release notes

V4.3.11

Overview

This firmware release provides optimizations, bug fixes, and fixes for security vulnerabilities.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added language support for Korean.
  • (Only available on GL-X750) Added some software packages: kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs.

Bug fixes

  • Fixed an issue with GL-MT300N-V2 where the dip switch and the UI display were reversed.
  • Fixed an issue with GL-MT300N-V2 where wireless terminals could not obtain an address after successfully switching to the Extend and WDS modes.
  • Fixed an issue where two routers acting as the VPN server and the VPN client respectively could not automatically reconnect after disconnection due to network volatility.
  • Fixed an issue where client devices connected through an ethernet cable would not automatically reconnect after the LAN IP address was modified.
  • Fixed a conflicted that occurred with GL-SFT1200 between PPPoE protocol with VLAN ID and hardware acceleration.
  • Fixed an error that happened when a device using PPPoE protocol first switched to the Extender mode and then restored the Route mode.
  • Fixed various known vulnerabilities.
4.3.10 2024-02-02
SHA256: 037c575e83670c41... SHA256: 36fe51d18c33a0ed... 🔗 share
Release notes

V4.3.10

Overview

This version mainly includes optimizations, bug fixes, and security vulnerability resolutions, as shown below.

This release is available for the following models:
GL-AR300M Shadow
GL-AR300M16 Shadow
GL-AR750 Creta
GL-AR750S-EXT Slate
GL-B1300 Convexa-B
GL-MT300N-V2 Mango
GL-MT1300 Beryl

Bug fixes

  • Fixed deadlock issue in mwan3.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.3.7 2023-09-13
SHA256: c2991461b836b2dc... SHA256: 3b0779dfa3bef2f4... 🔗 share
Release notes

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS faeture.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fiwith the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.

BUG fix

  • Fixed the TTL settings not taking effect when fw4 is used.
3.216 2023-03-21
SHA256: f9f34e4202474a13... SHA256: 7bd6580918547b3c... 🔗 share
Release notes

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

GL-AR300M16 Shadow ar300m16

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.27 2025-05-14
SHA256: 4ab5fc68dbafde7f... 🔗 share
Release notes

V4.3.27

Overview

This version mainly fixed some known bugs.

Bug Fixes

  • Fixed the issue where the transmit power was abnormal in certain situations.
4.3.25 2025-03-31
SHA256: 759b0263128754d0... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.22 2024-12-18
SHA256: e172328d65cf0322... 🔗 share
Release notes

V4.3.22

Overview

This version mainly includes new features.

Synchronized Updated Model

Shadow (GL-AR300M16)

New Features

  • Support web access in extender mode.

Bug Fixes

  • Fixed the issue where the external module display SMS icon is empty when clicked.
  • Fixed the issue where the cloud platform goes online, the model field of the device displays an error
4.3.18 2024-08-23
SHA256: 97354eaf6a7c2399... 🔗 share
Release notes

V4.3.18

Overview

This version fixes some security vulnerabilities.

Supported models

Slate (GL-AR750S), Creta (GL-AR750), Mudi (GL-E750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300).

4.3.17 2024-06-07
SHA256: 95ec97e950f51389... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.11 2024-03-20
SHA256: a3f5fa4642df519b... 🔗 share
Release notes

V4.3.11

Overview

This firmware release provides optimizations, bug fixes, and fixes for security vulnerabilities.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added language support for Korean.
  • (Only available on GL-X750) Added some software packages: kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs.

Bug fixes

  • Fixed an issue with GL-MT300N-V2 where the dip switch and the UI display were reversed.
  • Fixed an issue with GL-MT300N-V2 where wireless terminals could not obtain an address after successfully switching to the Extend and WDS modes.
  • Fixed an issue where two routers acting as the VPN server and the VPN client respectively could not automatically reconnect after disconnection due to network volatility.
  • Fixed an issue where client devices connected through an ethernet cable would not automatically reconnect after the LAN IP address was modified.
  • Fixed a conflicted that occurred with GL-SFT1200 between PPPoE protocol with VLAN ID and hardware acceleration.
  • Fixed an error that happened when a device using PPPoE protocol first switched to the Extender mode and then restored the Route mode.
  • Fixed various known vulnerabilities.
4.3.10 2024-02-02
SHA256: cdde3efa4b851c7b... 🔗 share
Release notes

V4.3.10

Overview

This version mainly includes optimizations, bug fixes, and security vulnerability resolutions, as shown below.

This release is available for the following models:
GL-AR300M Shadow
GL-AR300M16 Shadow
GL-AR750 Creta
GL-AR750S-EXT Slate
GL-B1300 Convexa-B
GL-MT300N-V2 Mango
GL-MT1300 Beryl

Bug fixes

  • Fixed deadlock issue in mwan3.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.3.7 2023-09-13
SHA256: e8ee30e99d6a23c7... 🔗 share
Release notes

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS faeture.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fiwith the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.

BUG fix

  • Fixed the TTL settings not taking effect when fw4 is used.
4.3.30 beta1 build 463 2026-05-29
SHA256: 3d26d38a0a468e55... 🔗 share
Release notes

V4.3.30

Overview

This version mainly fixed some known bugs and security vulnerabilities. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • 2026-05-29: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.3.30 beta1 build 462 2026-05-21
SHA256: 54dc1eed254a60a9...
Release notes

V4.3.30

Overview

This version mainly fixed some known bugs and security vulnerabilities. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • 2026-05-20: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.3.29 2026-04-10
SHA256: 4d3c4c79d9c52980... 🔗 share
Release notes

V4.3.29

Overview

This version mainly fixed some known bugs and security vulnerabilities.

3.216 2023-03-21
SHA256: 3a9d7437f74ba18c... 🔗 share

GL-AR750 Creta ar750

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.25 2025-03-31
SHA256: 42d36282c14fee28... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.18 2024-08-23
SHA256: dfbfeadf0217ae08... 🔗 share
Release notes

V4.3.18

Overview

This version fixes some security vulnerabilities.

Supported models

Slate (GL-AR750S), Creta (GL-AR750), Mudi (GL-E750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300).

4.3.17 2024-06-07
SHA256: 64012c9a9dcd0fec... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.11 2024-03-20
SHA256: 0c60bc5d41891c5a... 🔗 share
Release notes

V4.3.11

Overview

This firmware release provides optimizations, bug fixes, and fixes for security vulnerabilities.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added language support for Korean.
  • (Only available on GL-X750) Added some software packages: kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs.

Bug fixes

  • Fixed an issue with GL-MT300N-V2 where the dip switch and the UI display were reversed.
  • Fixed an issue with GL-MT300N-V2 where wireless terminals could not obtain an address after successfully switching to the Extend and WDS modes.
  • Fixed an issue where two routers acting as the VPN server and the VPN client respectively could not automatically reconnect after disconnection due to network volatility.
  • Fixed an issue where client devices connected through an ethernet cable would not automatically reconnect after the LAN IP address was modified.
  • Fixed a conflicted that occurred with GL-SFT1200 between PPPoE protocol with VLAN ID and hardware acceleration.
  • Fixed an error that happened when a device using PPPoE protocol first switched to the Extender mode and then restored the Route mode.
  • Fixed various known vulnerabilities.
4.3.10 2024-02-02
SHA256: 29adee8d85108123... 🔗 share
Release notes

V4.3.10

Overview

This version mainly includes optimizations, bug fixes, and security vulnerability resolutions, as shown below.

This release is available for the following models:
GL-AR300M Shadow
GL-AR300M16 Shadow
GL-AR750 Creta
GL-AR750S-EXT Slate
GL-B1300 Convexa-B
GL-MT300N-V2 Mango
GL-MT1300 Beryl

Bug fixes

  • Fixed deadlock issue in mwan3.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.3.7 2023-09-13
SHA256: 16312e117c274ddb... 🔗 share
Release notes

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS faeture.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fiwith the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.

BUG fix

  • Fixed the TTL settings not taking effect when fw4 is used.
3.216 2023-03-21
SHA256: f709078a339eae5d... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

GL-AR750S-EXT Slate ar750s

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.25 2025-04-03
SHA256: 41146b67407b85ca... SHA256: 4c0724f3eea9aa6b... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.18 2024-08-23
SHA256: 42ae2b9d791aa850... SHA256: e56f6cca24ada726... 🔗 share
Release notes

V4.3.18

Overview

This version fixes some security vulnerabilities.

Supported models

Slate (GL-AR750S), Creta (GL-AR750), Mudi (GL-E750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300).

4.3.17 2024-06-07
SHA256: a7e2fa8a81d6c016... SHA256: 913649705f9aaf7e... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.11 2024-03-20
SHA256: 720bab77fecfa992... SHA256: 9aa051f3b408e6e3... 🔗 share
Release notes

V4.3.11

Overview

This firmware release provides optimizations, bug fixes, and fixes for security vulnerabilities.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added language support for Korean.
  • (Only available on GL-X750) Added some software packages: kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs.

Bug fixes

  • Fixed an issue with GL-MT300N-V2 where the dip switch and the UI display were reversed.
  • Fixed an issue with GL-MT300N-V2 where wireless terminals could not obtain an address after successfully switching to the Extend and WDS modes.
  • Fixed an issue where two routers acting as the VPN server and the VPN client respectively could not automatically reconnect after disconnection due to network volatility.
  • Fixed an issue where client devices connected through an ethernet cable would not automatically reconnect after the LAN IP address was modified.
  • Fixed a conflicted that occurred with GL-SFT1200 between PPPoE protocol with VLAN ID and hardware acceleration.
  • Fixed an error that happened when a device using PPPoE protocol first switched to the Extender mode and then restored the Route mode.
  • Fixed various known vulnerabilities.
4.3.10 2024-02-06
SHA256: 94d2e880171a5ac9... SHA256: 74f2cbec2c38d1de... 🔗 share
Release notes

V4.3.10

Overview

This version mainly includes optimizations, bug fixes, and security vulnerability resolutions, as shown below.

This release is available for the following models:
GL-AR300M Shadow
GL-AR300M16 Shadow
GL-AR750 Creta
GL-AR750S-EXT Slate
GL-B1300 Convexa-B
GL-MT300N-V2 Mango
GL-MT1300 Beryl

Bug fixes

  • Fixed deadlock issue in mwan3.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.3.7 2023-09-13
SHA256: 176236202c7d01d2... SHA256: a78e2c2e0b465755... 🔗 share
Release notes

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS faeture.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fiwith the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.

BUG fix

  • Fixed the TTL settings not taking effect when fw4 is used.
4.7.2 2025-03-31
SHA256: a684d71fbf1cfe9c... SHA256: b45794c45a8387c7... 🔗 share
Release notes

V4.7.2

Overview

This version introduces several new features and enhancements that improve the interface interaction for overall user experience.

New Features

  • Added device initialization wizard, including administrator and WiFi password, networking, VPN and other core function settings.
  • Added the Cloud account login function, supporting device binding to the cloud from the firmware web page.
  • Added Domain Name List Subscription function, support VPN policy and parental control to subscribe to online domain name or IP list via URL.
  • Added the AP Isolation function.
  • Added the Luci Access Restriction function.
  • Added the Network Port Management page, supporting scheduled and restart of automatic Ethernet MAC updates, WAN/LAN port switching, and displaying network port negotiation rates.
  • Added NordVPN, PIA, Surfshark, Hideme, IPVanish WireGuard VPN, and support AzireVPN registration function.

Optimization

  • Optimized the process for manually adding the WireGuard client configuration file and supporting automatic key generation.
  • Optimized the process for configuring vendor profiles for VPN clients.
  • Optimized Repeater random MAC setting, supporting scheduled and restart of automatic Repeater MAC updates.
  • Optimized the flow of Multi-WAN load network status detection.
  • Optimized OpenVPN Client functionality to allow modification of configuration file names.
  • Optimized page names in the web Administration Panel so that the router is host name appears in the browser tab.
  • Optimized page interactions such as interface error messages and inputable drop-down list designs.
  • Upgraded Tor to version 0.4.8.9.
3.216 2023-03-21
SHA256: c4e5df3038c85dd9... SHA256: ba40149d13390016... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

GL-AX1800 Flint ax1800

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.3 2026-03-19
SHA256: a1aae18b9a7da1fc... SHA256: 13605b6b6e22e0bc... 🔗 share
Release notes

V4.8.3

Cautions

The OpenWRT version has been upgraded. Please do NOT keep settings when downgrading to an earlier version. Please backup your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12, support dco to improve OpenVPN performance.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.
  • Replaced NTPD with Chrony, which supports the NTS protocol.
  • Optimized the Repeater's detection logic of Captive Portal to be compatible with identifying more authentication pages in different formats.
  • Optimized the switching logic of the Repeater; when the internet is already connected, the repeater will not scan for available networks to ensure wireless communication quality.
  • Optimized the Upgrade function, replacing Release Candidate with Gray Release.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
  • Merge the patch related to CVE-2025-62526.
4.6.8 2024-10-17
SHA256: 5fb897cd054c9fe6... SHA256: b7a25ae95a4a9dc8... 🔗 share
Release notes

V4.6.8

Overview

This version mainly focuses on fixing a few known bugs.

Synchronized Updated Models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

Improvement

  • Upgrade AdGuard Home version to v0.107.52.

Bug Fixes

  • Fixed the issue where, after enabling the VPN client and using Global Proxy, enabling AdGuard Home to handle client requests resulted in only localhots 127.0.0.1 appearing in the client list on the settings page.
  • Fixed the issue that TCP port can be probed when WireGuard Server is enabled.
  • Fixed the issue where the 5G wireless disappeared after the device relayed an upstream device with a 5G channel set to 20M dfs.
  • Fixed the issue that resulted in unusual log messages.
  • Fixed the issue where the router's own DNS requests always went through the dnsmasq proxy after switching DNS settings on the page.
4.6.6 2024-09-26
SHA256: f1d58325de066e7c... SHA256: d53c67cd66bcb41a... 🔗 share
Release notes

V4.6.6

Overview

This version mainly focuses on fixing a few known bugs.

Supported Models

Flint (GL-AX1800), Slate AX (GL-AXT1800).

Bug Fixes

  • Fixed the issue that v4.2.3 reserved configuration upgrade to v4.6.4 would cause wirelessGUI loss.
  • Fixed the problem of abnormal messages appearing in the log.
4.6.4 2024-09-04
SHA256: f700427e06327737... SHA256: 5bf7a8bca5228cfe... 🔗 share
Release notes

V4.6.4

Overview

This version mainly focuses on fixing a few known bugs and fixes some security vulnerabilities to enhance the user experience.

Supported Models

GL-AX1800, GL-AXT1800, GL-MT2500/GL-MT2500A, GL-MT3000, GL-MT6000.

Improvement

  • Updated WiFi driver(MT3000).

Bug Fixes

  • Fixed an issue with DNS leaks when upgrading from version 4.5.x reserved configurations to 4.6.x with VPN connected.
  • Fixed the issue that when the 5G main network is not a DFS channel, the 5G main network page will be opened again with a prompt of about 3s for DFS channel availability detection.
  • Fixed a relay scan timeout issue when the WiFi was configured with DFS channels.
  • Fixed the issue where the relay icon did not turn gray when disconnecting the relay connection while the internet connection mode was set to relay and wired.
  • Fixed the issue where language packs were not retained after upgrading with preserved configuration.
  • Fixed the issue where PC WebDAV access would show no data, after enabling WebDAV, inserting a USB drive, and rebooting.
  • Fixed the issue where RTTY-WEB remote access encountered relay scan errors and failed to relay.
  • Fixed a crash of the device's WiFi driver when connecting with a D-Link DWA-192 AC1900 network adapter to 2.4G WiFi.
  • Corrected an issue where adding and applying any custom rule in parental control had no effect on Google Chrome.
  • Fixed an issue where trunks were configured with static IPs, and the trunks showed up as connected even though the trunks were disconnected.
  • Fixed the issue of DNS leakage when VPN Client and DNS encryption are enabled.
  • Corrected a problem where switching internet connection modes did not update the IP address in DDNS resolution.
  • Fixed an issue where videos and images on the USB drive could not be accessed after inserting a USB drive, enabling DLNA, and soft resetting the device.
  • Resolved a DNS leak issue when switching VPN policy from global proxy to IP/domain-based mode.
  • Fixed the issue that the client's hostname was reported to the relay's superior after the relay set a random MAC.
  • Fixed the issue that the WAN port does not show IPv6 address when connecting to a VPN client and then enabling IPv6.
  • Addressed a program crash caused by relay scanning when no other APs were nearby.
  • Corrected a crash caused by wireless scanning of SSIDs containing carriage return characters.
  • Fixed the issue where accessing the device management page using an IPv6 address displayed incorrect MAC cloning information for Ethernet and relay.
  • Fixed the issue where the WebDAV function did not work properly when using an account or password with a length of 64-bit characters.
  • Fixed the issue that after pulling Mullvad VPN configuration, when the corresponding Public Key is deleted from the Mullvad website and the configuration is pulled again, the IP address in the pulled configuration changes to 'The'.
  • Resolved the issue of relay scanning crashing when IBSS exists in the surrounding area.
  • Fixed the issue where firewall rules would occasionally disappear after rebooting the device following a connection to wgclient.
  • Fixed the issue where dip switch is bound to wireguard client, the device turns on ovpn client, and restarting the device causes vpn policy to fail.
  • Fixed the issue where the killswitch failed to work when the DNS service was proxied by the AdGuard program or an encrypted DNS program, and the VPN was in a connected state.
4.6.2 2024-07-09
SHA256: 3d83551a6c089e7e... SHA256: 7782494b60538e83... 🔗 share
Release notes

V4.6.2

Overview

This version mainly provides the following improvements:

  • Improved the user experience with the repeater feature. Resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Improved the display of IPv6 addresses, and added support for customization of the interface language packs.

Supported models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

New features

  • Added the Login Mode for Public Hotspots and the Camouflage Mode. This resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Added the option to use a randomized BSSID to prevent devices from being traced by BSSID.
  • Added the UI language pack management feature. This allows adding additional language packs and subscribing to language pack updates.
  • Added an option to choose whether the VPN interface uses manually configured DNS. This allows using the VPN's DNS servers, if Encrypted DNS or AdGuard Home is enabled.
  • Added support for port range forwarding and port forwarding rule prioritization options.
  • Added TTL, HL, and MTU options for each interface.
  • Added support for connecting to Wi-Fi via QR code.

Improvements

  • Optimized the repeater feature to enhance performance and user experience. Added support for configuring MAC address for SSIDs individually.
  • Optimized the display of IPv6 address on the Internet page and the Client page.
  • Optimized the MAC address setting logic to support cloning or setting random MAC addresses for each interface.
  • Optimized the status display on the Tethering interface to make a clear distinction between 'disabled' and 'enabled but no device'.
  • Optimized the port forwarding feature. It now has its own page within the admin panel and can function simultaneously as DMZ. The port opening (previously on the Firewall page) has been moved to the Security page.
  • Optimized the logic of jumping after LAN IP is modified so that users do not need to sign in again.
  • Optimized the logic of guest network enabling. If guest Wi-Fi is disabled, guest network will also be disabled.
  • Optimized the logic of toggle switches. When rebooting a device, the enabling status of corresponding services (such as VPN) will be set according to the status of the toggle switch.
  • Removed the length restriction on mobile phone number in SMS sending and forwarding.
  • Removed the option 'Force 20MHz Bandwidth For 2.4G' from the Repeater settings.
  • Upgraded AdGuard Home to version 0.107.46.

Bug fixes

  • Fixed an issue where reserved IP addresses were incorrectly sorted by IP if the IP address range was large.
  • Fixed instances where abnormal issues would occur during firmware grade when “keep settings” was selected during IPv6 mode.
  • Fixed an issue where the reset feature would not work when Tailscale was enabled.
  • Fixed an issue where parental controls would not properly resolve domain names using capital letters (e.g., WWW.GOOGLE.COM).
  • Fixed an issue where manually configured routes would not work in some cases when the VPN client was in custom routing proxy mode.
  • Fixed an issue where the cellular interface would incorrectly determine the internet status of the IPv6 protocol.
  • Fixed an issue where the manual DNS server address in the DNS interface would be invalid after disabling AdGuard Home.
  • Fixed an issue where the imported WireGuard profiles with multi-line AllowedIPs entries were parsed incorrectly.
  • Fixed an issue where re-uploading an OpenVPN profile ZIP file with an additional certificate file would not overwrite the old certificate file upload the first time. (This caused some configurations provided by the VPN service providers to not update properly when manually uploaded again.)
  • Fixed an issue where the router would not recognize USB cellular modems using the M2 EM05G model.
  • Fixed an issue that prevented the VPN from properly following the interface connection status for failover to function when using policy-based proxy mode.
4.5.16 2024-03-21
SHA256: abb4ff96acfff8ca... SHA256: 0e14896e9a796f3a... 🔗 share
Release notes

V4.5.16

Overview

This firmware release provides fixes to some bugs and security vulnerabilities.

Supported Models

GL-A1300 Slate Plus, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-MT3000 Beryl AX, GL-MT2500/GL-MT2500A Brume 2

Improvements

  • Optimized the client IP assignment policy in TAP-S2S mode when the device subnets of OpenVPN Client and OpenVPN Server were the same.
  • Upgraded Tailscale to version 1.58.2.

Bug fixes

  • Fixed an issue where multiple parsed AllowedIPs were incorrect when parsing the uploaded WireGuard client configuration files.
  • Fixed an IP conflict issue that occured when adding a client profile to WireGuard after modifying the PeerIP of the WireGuard server configuration via SSH.
  • Fixed an issue where the router’s Tailscale service data would be forwarded through a VPN tunnel when the VPN Client global mode was enabled.
  • Fixed an issue where inbound data from non-VPN interfaces would not trigger port forwarding rules when VPN was enabled.
  • Fixed an issue where some devices from the TAP-S2S OpenVPN client would not display properly on the client page.
  • Fixed an issue where the OpenVPN server certificate may be lost after rebooting the device.
  • Fixed an issue where the address’s description field was lost after upgrading to firmware v4.5.0 from v4.4.x when the user chose to keep router settings.
  • Fixed an issue where selecting manual mode on the MAC address page and entering the factory default MAC address on the ethernet page would result in an unsuccessful configuration even after connecting to the repeater successfully at first.
  • Fixed an issue where the network speed limit feature was still activated after enabling network speed limit, enabling network acceleration, and rebooting the device.
  • Fixed some known vulnerabilities.
4.5.0 2024-01-23
SHA256: 3c5a568948c9b6a8... SHA256: e29bfb1580653f24... 🔗 share
Release notes

V4.5.0

Overview

This release version mainly enhances network security and fixes known issues with network status detection, providing users with the option to manually add languages in the language community and the option to pre-emptively experience the new version. It is compatible with Full Cone NAT and SIP ALG features found in other routers. Optimization, bug fixing, and vulnerability repair for more vendors are shown below.

This release is available for the following models:
GL-A1300 Slate Plus
GL-AX1800 Flint
GL-AXT1800 Slate AX
GL-MT3000 Beryl AX
GL-MT2500/GL-MT2500A Brume 2
GL-X300B Collie

New features

  • Reconstructed mwan3 and renamed it as kmwan. Optimized failover and load balancing, as well as network status in various scenarios.
  • Added the Security configuration page.
  • Added grayscale testing design. Added RC version subscription and upgrade.
  • Added the communityization of language packs to support manual addition.
  • Added support for IPoE, and support for configuring VLAN ID during DHCP and static dialing.
  • Added Full Cone NAT function.
  • Added the SIP ALG option.
  • Added new temperature protection setting for MTK Wi-Fi.

Improvements

  • Optimized the side route UI interaction and add the option to turn off the DHCP server itself.
  • Optimized the restart process of the relay program.
  • [Only for GL-X300B Collie] Optimized the functionality of RS485, the UI, and localization.
  • Optimized the Tailscale mechanism.
  • Updated language files and pull translation scripts.

Bug fixes

  • Fixed an issue where the interface jumped due to the incorrect change in the client's online time.
  • Fixed an issue with the TTL settings not taking effect.
  • Fixed an issue where scanning always indicated that it was in DFS when all interfaces were disabled.
  • Fixed an issue of failing to enable Wi-Fi for the first time after upgrading.
  • Fixed an issue of failing to connect to the AP due to a failure to parse IE_HT_CAP.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.4.6 2023-09-08
SHA256: efd26270899b9dc8... SHA256: 21441ec0d84cac9f... 🔗 share
Release notes

V4.4.6 - Sep 8,2023

VPN

  • Fixed the problem that the OpenVPN client cannot access the Internet after dialing up, either by rebooting the router or by restarting the feature.

WireGuard

  • Fixed the problem that WireGuard client gets error 'Error: inet6 prefix is expected rather than' when connecting to server.
  • Fixed the problem that the WireGuard client of the device under test does not disconnect after the WireGuard server of the device accompanying the test is shut down, and keeps showing the connection status.

Repeater

  • Fixed the problem that the wireless network connection is abnormal after the router repeater DFS channel.

Tailscale

  • Fixed the problem that when using PPPoE dialup, the Internet cannot be accessed when tailscale is enabled.
  • Fixed the problem that the Good Cloud platform fails to connect when Tailscale is enabled.

Clients

  • Fixed the problem that the black/white list function is not compatible with the old version of blacklist.

Upgrade

  • Fixed the problem that online upgrade reports error '-4,fetch firmware name fail: network unreachable'.

DDNS

  • Fixed the problem that all TCP ports are opened when DDNS is enabled to allow http/https access in reserved configurations.

LAN

  • Fixed the problem that br-lan occasionally hangs when changing LAN IP.
4.2.3 2023-07-06
SHA256: 11c92b9d51eb7018... SHA256: d21f1492396ffb92... 🔗 share
Release notes

Bug Fixes

Fixed the problem that after the MT3000 relays the 160M Hz hotspot, the AP becomes 20M.
Fixed the problem that the AX/AXT1800 cannot access the AP itself after relaying the DFS 140 channel.
Fixed the problem that parental control cannot block blacklist websites in newer browsers.
Fixed the externder working mode, the superior cannot ping the subordinate.
Fixed the problem that openvpn port forwarding fails after the reserved configuration is upgraded.
Fix the problem that mqtt cannot report SSID.
Fixed the problem that ddns occasional interface return error.
Fixed The relay cannot connect to Huawei TC7102 160MHz 5GWiFi.
Fix single sim card slot does not return dual sim card slot information.
Fixed the problem that after the adguardhome function is turned on on the A1300 and the adguardhome is turned off, the visitor has no network.
Fixed the problem that Openvpn Server and wireguard Server shut down remote access to the LAN subnet, but the Openvpn and wireguard clients can still access the IP address of the PC on the LAN side of the server.
Fixed the AP bridge mode, the bridge is not successful. The address assigned by the superior cannot be obtained.
Support-EM160R-EM060K-EM120K-RM520N-modem.
Fixed the problem that A1300 cannot recognize USB3.0 external modem.
Fixed the problem of abnormal equipment caused by the time zone or 160M bandwidth issued by the GoodCloud.
Correct the display problem of the LED light in the unconnected network mode.
Fixed the problem of unsuccessful dialing using external modem, QMI and QCM protocol dialing.
Roll back MTK SDK from v7.6.7.0 to v7.6.6.1.

4.2.1 2023-04-14
SHA256: 42a357d3afe6c308... SHA256: b1fdb93ae45abf05... 🔗 share
Release notes

Bug Fixes

Fixed a problem where the WiFi configuration page showed unavailable channel options.
Fixed a problem where NordVPN could not resolve DNS after keeping settings upgrade.
Fixed a problem where GL-MT3000 failed to recognize USB3.0 modem.
Fixed a problem where the IPV6 rate limiting does not take effect.
Fixed a problem where GL-MT3000 failed to repeat to iPhone 13 and TP-LINK ACR700.
Fixed a memory leak problem in GL-MT3000 when using QCM protocol.
Fixed a probabilistic issue where GL-MT3000 could not apply OpenVPN username and password.
Fixed switch button not taking effect when parental control is enabled on GL-A1300.
Fixed a BUG where clients could not access the internet after failover.

Optimizations

Disabled nginx access logs.
Optimized the MWAN3 online detection threshold.
Optimized the synchronization of configuration files in abnormal situations.
Optimized the repeater scan time of GL-MT3000.

Software Upgrade

Upgraded AdguardHome to V0.107.26.

4.2.0 2023-03-10
SHA256: 13097be99a515877... SHA256: 51e9d08bd8c85bdd... 🔗 share
Release notes

Optimization

Improved IPv6 LAN Mode options. Separates the native and passthrough modes.
Improved the results and hints of the DDNS test.
Improved drop-in gateway feature with DHCP-based solution to increase stability.
Improved LED lighting logic to ensure consistency with the UI.
Improved interaction for MAC address cloning.
Improved networking status alerts in Internet page.
Improved interface tracking settings description for Multi-WAN.
Improved login page with automatic focus to password input box.
Improved VPN client configuration file view with files sorted by name.
Improved the switch name in the VPN global options for whether the GL.iNet service uses VPN or not.
Improved the interaction of set read-only users to read-write users in network storage.
Improved ADGuard Home feature to support seeing which client the request is coming from.

Language

Added German language.

New feature

Added Parental Control feature.
Added Zerotier feature.
Added Tailscale feature.
Added Clear Traffic Statistics button for in client page.
Added DHCP Gateway option for LAN.
Added SSID Visibility option for guest Wi-Fi.
Added support for GoodCloud alerts when new clients join.
Added support for comments for domain and IP profiles in VPN policy.

4.8.4 beta2 build 973 2026-03-26
SHA256: bd4052d5f4e99a63... SHA256: 59a894d689e6cedf... 🔗 share
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for the AmneziaWG 2.0 obfuscation protocol.
4.8.4 beta1 build 972 2026-03-20
SHA256: cbe17ed85b0925d7... SHA256: 61b3b4ebba82182f...
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for AmneziaWG obfuscation protocol.
4.8.3 2025-12-26
SHA256: 80b30e6762d7d071... SHA256: 74088bf21f7f51ae... 🔗 share
📝 Removed from GL.iNet download site on 2026-03-19
Release notes

V4.8.3

Cautions

The OpenWRT version has been upgraded. Please do NOT keep settings when downgrading to an earlier version. Please backup your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12, support dco to improve OpenVPN performance.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.
  • Replaced NTPD with Chrony, which supports the NTS protocol.
  • Optimized the Repeater's detection logic of Captive Portal to be compatible with identifying more authentication pages in different formats.
  • Optimized the switching logic of the Repeater; when the internet is already connected, the repeater will not scan for available networks to ensure wireless communication quality.
  • Optimized the Upgrade function, replacing Release Candidate with Gray Release.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
  • Merge the patch related to CVE-2025-62526.
4.8.2 2025-08-19
SHA256: 542a1c32dc2bc8a7... SHA256: 9a949c3ff86a2f53... 🔗 share
📝 Removed from GL.iNet download site on 2026-03-19
Release notes

V4.8.2

Cautions

The openwrt version has been upgraded. Please do NOT keep settings when you downgrade to a version earlier than this version. Please backup your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance, allowing support for enabling multiple VPN clients at the same time.
  • Added VPN composite policy, allowing traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only when the VPN policy is based on MAC.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added support for HTTPS in RTTY.
  • Added a one-click option to send logs to technical support.
  • Added support for IPv6 in VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.
3.214 2025-07-02
SHA256: 8146d2fd1acf93d2... 🔗 share
Release notes

Important bugfix

  1. fix ipv6: test-ipv6.com report fail
  2. fix router policy mem leak
  3. fix "cmnos_thread.c: 3656" type of wifi crash

New features

  1. supports side router setup
3.216 2023-03-21
SHA256: cb466a4a78dd4f57... 🔗 share

GL-AXT1800 Slate AX axt1800

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.3 2026-04-22
SHA256: fdb284e1ac9886b7... SHA256: 72061649da98b5b6... 🔗 share
Release notes

V4.8.3

Overview

This version mainly fixed some known bugs and security vulnerabilities.

4.8.2 2025-09-04
SHA256: 972ab381e1e6af52... SHA256: d597fa4182878f47... 🔗 share
Release notes

V4.8.2

Cautions

The OpenWRT version has been upgraded. Please do NOT keep settings when downgrading to an earlier version. Please backup your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized toggle switch functionality to support Repeater, Wi-Fi and LED light control.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
4.6.11 2024-12-15
SHA256: fc9bf38d930e7281... SHA256: 3e11363256d90f29... 🔗 share
Release notes

V4.6.11

Overview

This version mainly fixes some known bugs.

Synchronized Updated Model

Slate AX (GL-AXT1800).

Bug Fixes

  • Fixed the issue of abnormal transmit power in some cases.
  • Fixed the problem of abnormal display of channel list in some cases.
4.6.8 2024-10-17
SHA256: eb11db2e26490e70... SHA256: faef007cf2a97429... 🔗 share
Release notes

V4.6.8

Overview

This version mainly focuses on fixing a few known bugs.

Synchronized Updated Models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

Improvement

  • Upgrade AdGuard Home version to v0.107.52.

Bug Fixes

  • Fixed the issue where, after enabling the VPN client and using Global Proxy, enabling AdGuard Home to handle client requests resulted in only localhots 127.0.0.1 appearing in the client list on the settings page.
  • Fixed the issue that TCP port can be probed when WireGuard Server is enabled.
  • Fixed the issue where the 5G wireless disappeared after the device relayed an upstream device with a 5G channel set to 20M dfs.
  • Fixed the issue that resulted in unusual log messages.
  • Fixed the issue where the router's own DNS requests always went through the dnsmasq proxy after switching DNS settings on the page.
4.6.4 2024-09-05
SHA256: f5912ed8f1add984... SHA256: dde4f680ad56c911... 🔗 share
Release notes

V4.6.4

Overview

This version mainly focuses on fixing a few known bugs and fixes some security vulnerabilities to enhance the user experience.

Supported Models

GL-AX1800, GL-AXT1800, GL-MT2500/GL-MT2500A, GL-MT3000, GL-MT6000.

Improvement

  • Updated WiFi driver(MT3000).

Bug Fixes

  • Fixed an issue with DNS leaks when upgrading from version 4.5.x reserved configurations to 4.6.x with VPN connected.
  • Fixed the issue that when the 5G main network is not a DFS channel, the 5G main network page will be opened again with a prompt of about 3s for DFS channel availability detection.
  • Fixed a relay scan timeout issue when the WiFi was configured with DFS channels.
  • Fixed the issue where the relay icon did not turn gray when disconnecting the relay connection while the internet connection mode was set to relay and wired.
  • Fixed the issue where language packs were not retained after upgrading with preserved configuration.
  • Fixed the issue where PC WebDAV access would show no data, after enabling WebDAV, inserting a USB drive, and rebooting.
  • Fixed the issue where RTTY-WEB remote access encountered relay scan errors and failed to relay.
  • Fixed a crash of the device's WiFi driver when connecting with a D-Link DWA-192 AC1900 network adapter to 2.4G WiFi.
  • Corrected an issue where adding and applying any custom rule in parental control had no effect on Google Chrome.
  • Fixed an issue where trunks were configured with static IPs, and the trunks showed up as connected even though the trunks were disconnected.
  • Fixed the issue of DNS leakage when VPN Client and DNS encryption are enabled.
  • Corrected a problem where switching internet connection modes did not update the IP address in DDNS resolution.
  • Fixed an issue where videos and images on the USB drive could not be accessed after inserting a USB drive, enabling DLNA, and soft resetting the device.
  • Resolved a DNS leak issue when switching VPN policy from global proxy to IP/domain-based mode.
  • Fixed the issue that the client's hostname was reported to the relay's superior after the relay set a random MAC.
  • Fixed the issue that the WAN port does not show IPv6 address when connecting to a VPN client and then enabling IPv6.
  • Addressed a program crash caused by relay scanning when no other APs were nearby.
  • Corrected a crash caused by wireless scanning of SSIDs containing carriage return characters.
  • Fixed the issue where accessing the device management page using an IPv6 address displayed incorrect MAC cloning information for Ethernet and relay.
  • Fixed the issue where the WebDAV function did not work properly when using an account or password with a length of 64-bit characters.
  • Fixed the issue that after pulling Mullvad VPN configuration, when the corresponding Public Key is deleted from the Mullvad website and the configuration is pulled again, the IP address in the pulled configuration changes to 'The'.
  • Resolved the issue of relay scanning crashing when IBSS exists in the surrounding area.
  • Fixed the issue where firewall rules would occasionally disappear after rebooting the device following a connection to wgclient.
  • Fixed the issue where dip switch is bound to wireguard client, the device turns on ovpn client, and restarting the device causes vpn policy to fail.
  • Fixed the issue where the killswitch failed to work when the DNS service was proxied by the AdGuard program or an encrypted DNS program, and the VPN was in a connected state.
4.6.2 2024-07-09
SHA256: a3766797f96c0982... SHA256: 0102f878608f31e9... 🔗 share
Release notes

V4.6.2

Overview

This version mainly provides the following improvements:

  • Improved the user experience with the repeater feature. Resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Improved the display of IPv6 addresses, and added support for customization of the interface language packs.

Supported models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

New features

  • Added the Login Mode for Public Hotspots and the Camouflage Mode. This resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Added the option to use a randomized BSSID to prevent devices from being traced by BSSID.
  • Added the UI language pack management feature. This allows adding additional language packs and subscribing to language pack updates.
  • Added an option to choose whether the VPN interface uses manually configured DNS. This allows using the VPN's DNS servers, if Encrypted DNS or AdGuard Home is enabled.
  • Added support for port range forwarding and port forwarding rule prioritization options.
  • Added TTL, HL, and MTU options for each interface.
  • Added support for connecting to Wi-Fi via QR code.

Improvements

  • Optimized the repeater feature to enhance performance and user experience. Added support for configuring MAC address for SSIDs individually.
  • Optimized the display of IPv6 address on the Internet page and the Client page.
  • Optimized the MAC address setting logic to support cloning or setting random MAC addresses for each interface.
  • Optimized the status display on the Tethering interface to make a clear distinction between 'disabled' and 'enabled but no device'.
  • Optimized the port forwarding feature. It now has its own page within the admin panel and can function simultaneously as DMZ. The port opening (previously on the Firewall page) has been moved to the Security page.
  • Optimized the logic of jumping after LAN IP is modified so that users do not need to sign in again.
  • Optimized the logic of guest network enabling. If guest Wi-Fi is disabled, guest network will also be disabled.
  • Optimized the logic of toggle switches. When rebooting a device, the enabling status of corresponding services (such as VPN) will be set according to the status of the toggle switch.
  • Removed the length restriction on mobile phone number in SMS sending and forwarding.
  • Removed the option 'Force 20MHz Bandwidth For 2.4G' from the Repeater settings.
  • Upgraded AdGuard Home to version 0.107.46.

Bug fixes

  • Fixed an issue where reserved IP addresses were incorrectly sorted by IP if the IP address range was large.
  • Fixed instances where abnormal issues would occur during firmware grade when “keep settings” was selected during IPv6 mode.
  • Fixed an issue where the reset feature would not work when Tailscale was enabled.
  • Fixed an issue where parental controls would not properly resolve domain names using capital letters (e.g., WWW.GOOGLE.COM).
  • Fixed an issue where manually configured routes would not work in some cases when the VPN client was in custom routing proxy mode.
  • Fixed an issue where the cellular interface would incorrectly determine the internet status of the IPv6 protocol.
  • Fixed an issue where the manual DNS server address in the DNS interface would be invalid after disabling AdGuard Home.
  • Fixed an issue where the imported WireGuard profiles with multi-line AllowedIPs entries were parsed incorrectly.
  • Fixed an issue where re-uploading an OpenVPN profile ZIP file with an additional certificate file would not overwrite the old certificate file upload the first time. (This caused some configurations provided by the VPN service providers to not update properly when manually uploaded again.)
  • Fixed an issue where the router would not recognize USB cellular modems using the M2 EM05G model.
  • Fixed an issue that prevented the VPN from properly following the interface connection status for failover to function when using policy-based proxy mode.
4.5.16 2024-03-21
SHA256: 96d2631ec6f27194... SHA256: c516a96fd52d744d... 🔗 share
Release notes

V4.5.16

Overview

This firmware release provides fixes to some bugs and security vulnerabilities.

Supported Models

GL-A1300 Slate Plus, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-MT3000 Beryl AX, GL-MT2500/GL-MT2500A Brume 2

Improvements

  • Optimized the client IP assignment policy in TAP-S2S mode when the device subnets of OpenVPN Client and OpenVPN Server were the same.
  • Upgraded Tailscale to version 1.58.2.

Bug fixes

  • Fixed an issue where multiple parsed AllowedIPs were incorrect when parsing the uploaded WireGuard client configuration files.
  • Fixed an IP conflict issue that occured when adding a client profile to WireGuard after modifying the PeerIP of the WireGuard server configuration via SSH.
  • Fixed an issue where the router’s Tailscale service data would be forwarded through a VPN tunnel when the VPN Client global mode was enabled.
  • Fixed an issue where inbound data from non-VPN interfaces would not trigger port forwarding rules when VPN was enabled.
  • Fixed an issue where some devices from the TAP-S2S OpenVPN client would not display properly on the client page.
  • Fixed an issue where the OpenVPN server certificate may be lost after rebooting the device.
  • Fixed an issue where the address’s description field was lost after upgrading to firmware v4.5.0 from v4.4.x when the user chose to keep router settings.
  • Fixed an issue where selecting manual mode on the MAC address page and entering the factory default MAC address on the ethernet page would result in an unsuccessful configuration even after connecting to the repeater successfully at first.
  • Fixed an issue where the network speed limit feature was still activated after enabling network speed limit, enabling network acceleration, and rebooting the device.
  • Fixed some known vulnerabilities.
4.5.0 2024-01-23
SHA256: dd59b3e6b4e8e5b5... SHA256: 99eba427a33b1200... 🔗 share
Release notes

V4.5.0

Overview

This release version mainly enhances network security and fixes known issues with network status detection, providing users with the option to manually add languages in the language community and the option to pre-emptively experience the new version. It is compatible with Full Cone NAT and SIP ALG features found in other routers. Optimization, bug fixing, and vulnerability repair for more vendors are shown below.

This release is available for the following models:
GL-A1300 Slate Plus
GL-AX1800 Flint
GL-AXT1800 Slate AX
GL-MT3000 Beryl AX
GL-MT2500/GL-MT2500A Brume 2
GL-X300B Collie

New features

  • Reconstructed mwan3 and renamed it as kmwan. Optimized failover and load balancing, as well as network status in various scenarios.
  • Added the Security configuration page.
  • Added grayscale testing design. Added RC version subscription and upgrade.
  • Added the communityization of language packs to support manual addition.
  • Added support for IPoE, and support for configuring VLAN ID during DHCP and static dialing.
  • Added Full Cone NAT function.
  • Added the SIP ALG option.
  • Added new temperature protection setting for MTK Wi-Fi.

Improvements

  • Optimized the side route UI interaction and add the option to turn off the DHCP server itself.
  • Optimized the restart process of the relay program.
  • [Only for GL-X300B Collie] Optimized the functionality of RS485, the UI, and localization.
  • Optimized the Tailscale mechanism.
  • Updated language files and pull translation scripts.

Bug fixes

  • Fixed an issue where the interface jumped due to the incorrect change in the client's online time.
  • Fixed an issue with the TTL settings not taking effect.
  • Fixed an issue where scanning always indicated that it was in DFS when all interfaces were disabled.
  • Fixed an issue of failing to enable Wi-Fi for the first time after upgrading.
  • Fixed an issue of failing to connect to the AP due to a failure to parse IE_HT_CAP.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.4.6 2023-09-08
SHA256: 32e32e90a68003b7... SHA256: 57c909834036f242... 🔗 share
Release notes

V4.4.6 - Sep 8,2023

VPN

  • Fixed the problem that the OpenVPN client cannot access the Internet after dialing up, either by rebooting the router or by restarting the feature.

WireGuard

  • Fixed the problem that WireGuard client gets error 'Error: inet6 prefix is expected rather than' when connecting to server.
  • Fixed the problem that the WireGuard client of the device under test does not disconnect after the WireGuard server of the device accompanying the test is shut down, and keeps showing the connection status.

Repeater

  • Fixed the problem that the wireless network connection is abnormal after the router repeater DFS channel.

Tailscale

  • Fixed the problem that when using PPPoE dialup, the Internet cannot be accessed when tailscale is enabled.
  • Fixed the problem that the Good Cloud platform fails to connect when Tailscale is enabled.

Clients

  • Fixed the problem that the black/white list function is not compatible with the old version of blacklist.

Upgrade

  • Fixed the problem that online upgrade reports error '-4,fetch firmware name fail: network unreachable'.

DDNS

  • Fixed the problem that all TCP ports are opened when DDNS is enabled to allow http/https access in reserved configurations.

LAN

  • Fixed the problem that br-lan occasionally hangs when changing LAN IP.
4.2.3 2023-07-06
SHA256: 4911ff9688ba170c... SHA256: a2793d1fe268fd7b... 🔗 share
Release notes

Bug Fixes

Fixed the problem that after the MT3000 relays the 160M Hz hotspot, the AP becomes 20M.
Fixed the problem that the AX/AXT1800 cannot access the AP itself after relaying the DFS 140 channel.
Fixed the problem that parental control cannot block blacklist websites in newer browsers.
Fixed the externder working mode, the superior cannot ping the subordinate.
Fixed the problem that openvpn port forwarding fails after the reserved configuration is upgraded.
Fix the problem that mqtt cannot report SSID.
Fixed the problem that ddns occasional interface return error.
Fixed The relay cannot connect to Huawei TC7102 160MHz 5GWiFi.
Fix single sim card slot does not return dual sim card slot information.
Fixed the problem that after the adguardhome function is turned on on the A1300 and the adguardhome is turned off, the visitor has no network.
Fixed the problem that Openvpn Server and wireguard Server shut down remote access to the LAN subnet, but the Openvpn and wireguard clients can still access the IP address of the PC on the LAN side of the server.
Fixed the AP bridge mode, the bridge is not successful. The address assigned by the superior cannot be obtained.
Support-EM160R-EM060K-EM120K-RM520N-modem.
Fixed the problem that A1300 cannot recognize USB3.0 external modem.
Fixed the problem of abnormal equipment caused by the time zone or 160M bandwidth issued by the GoodCloud.
Correct the display problem of the LED light in the unconnected network mode.
Fixed the problem of unsuccessful dialing using external modem, QMI and QCM protocol dialing.
Roll back MTK SDK from v7.6.7.0 to v7.6.6.1.

4.2.1 2023-04-14
SHA256: 4d50428028b63b35... SHA256: 11a2cceb95fc5530... 🔗 share
Release notes

Optimizations

Disabled nginx access logs.
Optimized the MWAN3 online detection threshold.
Optimized the synchronization of configuration files in abnormal situations.
Optimized the repeater scan time of GL-MT3000.

Software Upgrade

Upgraded AdguardHome to V0.107.26.

Bug Fixes

Fixed a problem where the WiFi configuration page showed unavailable channel options.
Fixed a problem where NordVPN could not resolve DNS after keeping settings upgrade.
Fixed a problem where GL-MT3000 failed to recognize USB3.0 modem.
Fixed a problem where the IPV6 rate limiting does not take effect.
Fixed a problem where GL-MT3000 failed to repeat to iPhone 13 and TP-LINK ACR700.
Fixed a memory leak problem in GL-MT3000 when using QCM protocol.
Fixed a probabilistic issue where GL-MT3000 could not apply OpenVPN username and password.
Fixed switch button not taking effect when parental control is enabled on GL-A1300.
Fixed a BUG where clients could not access the internet after failover.

4.2.0 2023-03-10
SHA256: 425b33d921ccf12a... SHA256: 0112ba93ff1be23f... 🔗 share
Release notes

Language

Added German language.

New feature

Added Parental Control feature.
Added Zerotier feature.
Added Tailscale feature.
Added Clear Traffic Statistics button for in client page.
Added DHCP Gateway option for LAN.
Added SSID Visibility option for guest Wi-Fi.
Added support for GoodCloud alerts when new clients join.
Added support for comments for domain and IP profiles in VPN policy.

Optimization

Improved IPv6 LAN Mode options. Separates the native and passthrough modes.
Improved the results and hints of the DDNS test.
Improved drop-in gateway feature with DHCP-based solution to increase stability.
Improved LED lighting logic to ensure consistency with the UI.
Improved interaction for MAC address cloning.
Improved networking status alerts in Internet page.
Improved interface tracking settings description for Multi-WAN.
Improved login page with automatic focus to password input box.
Improved VPN client configuration file view with files sorted by name.
Improved the switch name in the VPN global options for whether the GL.iNet service uses VPN or not.
Improved the interaction of set read-only users to read-write users in network storage.
Improved ADGuard Home feature to support seeing which client the request is coming from.

4.8.4 2026-04-09
SHA256: 1a9712df23684e66... SHA256: b00c9a4db40537c5... 🔗 share
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs and security vulnerabilities.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for the AmneziaWG 2.0 obfuscation protocol.
4.8.3 beta2 build 973 2026-03-26
SHA256: 4e472dd8f3d5b471... SHA256: e2f54d61c306df44... 🔗 share
📝 Removed from GL.iNet download site on 2026-04-09
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for the AmneziaWG 2.0 obfuscation protocol.
4.8.3 beta1 build 972 2026-03-19
SHA256: 2be012b58a2cb114... SHA256: 70e010ee55fddd1b...
Release notes

V4.8.3

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for AmneziaWG obfuscation protocol.

GL-B1300 Convexa-B b1300

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.25 2025-03-31
SHA256: af57a7ca1e49d0e7... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.18 2024-08-23
SHA256: 0bfdd14ca067eb5b... 🔗 share
Release notes

V4.3.18

Overview

This version fixes some security vulnerabilities.

Supported models

Slate (GL-AR750S), Creta (GL-AR750), Mudi (GL-E750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300).

4.3.17 2024-06-07
SHA256: 067efcdb98f2173b... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.11 2024-03-20
SHA256: 2dfab1bacd5b329a... 🔗 share
Release notes

V4.3.11

Overview

This firmware release provides optimizations, bug fixes, and fixes for security vulnerabilities.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added language support for Korean.
  • (Only available on GL-X750) Added some software packages: kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs.

Bug fixes

  • Fixed an issue with GL-MT300N-V2 where the dip switch and the UI display were reversed.
  • Fixed an issue with GL-MT300N-V2 where wireless terminals could not obtain an address after successfully switching to the Extend and WDS modes.
  • Fixed an issue where two routers acting as the VPN server and the VPN client respectively could not automatically reconnect after disconnection due to network volatility.
  • Fixed an issue where client devices connected through an ethernet cable would not automatically reconnect after the LAN IP address was modified.
  • Fixed a conflicted that occurred with GL-SFT1200 between PPPoE protocol with VLAN ID and hardware acceleration.
  • Fixed an error that happened when a device using PPPoE protocol first switched to the Extender mode and then restored the Route mode.
  • Fixed various known vulnerabilities.
4.3.10 2024-02-06
SHA256: 7cab38bb7d474b56... 🔗 share
Release notes

V4.3.10

Overview

This version mainly includes optimizations, bug fixes, and security vulnerability resolutions, as shown below.

This release is available for the following models:
GL-AR300M Shadow
GL-AR300M16 Shadow
GL-AR750 Creta
GL-AR750S-EXT Slate
GL-B1300 Convexa-B
GL-MT300N-V2 Mango
GL-MT1300 Beryl

Bug fixes

  • Fixed deadlock issue in mwan3.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.3.7 2023-09-13
SHA256: 8a65e203106848f2... 🔗 share
Release notes

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS faeture.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fiwith the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.

BUG fix

  • Fixed the TTL settings not taking effect when fw4 is used.
4.3.26 2026-05-21
Firmware (.bin) archived
SHA256: 40381aff07185381... 🔗 share
📝 Removed from GL.iNet download site on 2026-05-25
Release notes

V4.3.26

Overview

This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • 2026-05-20: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
3.216 2023-04-26
SHA256: cedf439b25bebabd... 🔗 share
Release notes

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

GL-B2200 Velica b2200

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
3.218 2024-07-09
SHA256: 07e03f98b136ba0a... 🔗 share
Release notes

V3.218

Overview

This firmware release provides fixes to various bugs and security vulnerabilities.

Supported Models

Velica (GL-B2200), Brume (GL-MV1000), Brume-W (GL-MV1000W), Microuter (GL-USB150), microuter-N300, GL-SF1200.

Bug fixes

  • Fixed an issue that the client device of the router could not get an IP address if the router as a VPN client disconnects and reconnects with an OpenVPN server in S2S-TAP mode.
3.216 2023-04-26
SHA256: 6ba25013d5cb38b3... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

GL-B3000 Marble b3000

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.5.22 2025-04-07
SHA256: 4beef3c6ca44d3fd... 🔗 share
Release notes

V4.5.22

Overview

This version fixed some security vulnerabilities.

4.5.19 2024-08-26
SHA256: f865155b7e309405... 🔗 share
Release notes

V4.5.19

Overview

This version fixes some security vulnerabilities.

Supported Models

GL-X300B Collie, GL-A1300 Slate Plus, GL-B3000 Marble.

4.5.18 2024-07-31
SHA256: c2bc7ef1b3063bda... 🔗 share
Release notes

V4.5.18

Overview

This firmware version mainly fixes bugs.

Supported Models

GL-B3000

Improvements

Bug Fixes

  • Fixed an issue where the device cloned the MAC of the PC on the LAN side and then switched the WAN port to LAN, and the MAC addresses conflicted.
  • Fixed the issue that the device crashes when the manual MAC clone input is all 0 during relay networking.
  • Fixed the issue that after 5G WiFi DFS channel detects radar signal evasion, setting DFS channel in the same band will cause wireless not to start.
  • Fixed the issue that the parental control ruleset does not take effect.
  • Fixed the issue that MAC address cloning of WAN2 port did not work in some cases.
  • Fixed an issue where the relay interface MAC address was not synchronized when the MAC address was occasionally switched from the cloned client MAC back to the factory setting.
  • Fixed the issue that if you modify 2.4G WiFi with 40 bandwidth to relay 20 bandwidth WiFi, and then switch to relay 5G WiFi without disconnecting the relay, 2.4G WiFi bandwidth is still 20.
  • Fixed the problem of incorrect channel change after restarting with specific bandwidth setting.
  • Fixed the problem of duplicate configuration prompt after VLAN ID deletion.
  • Fixed the issue that modifying 5G WiFi encryption and changing wireless mode may cause the MAC to change to 0 and WiFi cannot be searched.
  • Fixed the issue that after relaying a WiFi with Chinese characters in the SSID, the display is not normal when using the iw dev command.
  • Fixed the issue that the 5G 144 channel does not have DFS channel identification when the WiFi country code is JP.
  • Fixed the issue that the old VLAN ID value of WAN2 is not cleared when the device is in Dual WAN mode and the network is restored by pressing the reset button 4S on the device.
  • Fixed the issue that the relay scanning timeout occurs when the AP is in DFS state.
  • Fixed the issue that some WiFi with special characters cannot be relayed.
  • Fixed the issue that the device can not get IPV6 address when switching to AP mode and then switching back to routing mode after IPV6 is enabled.
  • Fixed the issue that the IPV6 address is not reachable when the device is switched to dual WAN mode and the cable of WAN2 port is switched to WAN1 port.
  • Fixed the issue that the superior did not configure the VLAN ID, and after setting the VLAN ID value to 1, the device can get the IP address but cannot access the Internet.
  • Fixed the issue that the device will fail to connect to 2.4G WiFi when relaying data in the known list for the first time, and will automatically switch to other WiFi in the known list.
  • Fix the issue that the page prompts abnormality when the device opens dual WAN mode and unplugs the WAN1 port cable when configuring the WAN2 port.
  • Fixed the issue that setting the wireless timer switch and switching the transmit power in the timer task does not take effect after the port number of HTTP is modified.
  • Fixed the issue that the relay scanning page prompts that the EAP network is not supported to be relayed, but it can be scanned and relayed successfully in the test result.
4.5.15 2024-07-17
SHA256: 9ea1477db40a0e64... 🔗 share
Release notes

V4.5.15

Overview

This firmware version mainly fixes bugs.

Supported Models

GL-B3000

Improvements

Bug Fixes

  • Fixed the issue that SSID or Wi-Fi password with special characters would cause the Wi-Fi to fail to start up.
  • Fixed the issue that encrypted DNS may be leaked under special scenarios.
  • Fixed the issue where 5G Wi-Fi would probabilistically have a wrong MAC address under certain operations, causing the Wi-Fi to not be searched.
  • Fixed the issue that after enabling Tailscale remote access, the device rebooted and the accompanying test device could not access the tested subordinate PC and the superior WAN-side PC.
  • Fixed the issue where Tailscale had memory leaks under certain circumstances.
  • Fixed the issue that when the device client is set to whitelist and switched to AP or WDS mode, the device cannot get the IP address assigned by the superior.
  • Fixed the issue that the configuration may be lost after the device is powered off when switching black and white lists multiple times in quick succession.
4.5.12 2024-07-02
SHA256: c486dd37c9217855... 🔗 share
Release notes

V4.5.12

Overview

This version is mainly to optimize and fix bugs.

Supported Models

GL-B3000

Improvements

  • Optimize WireGuard upload rate.
  • Update tailscale version to 1.66.4.

Bug Fixes

  • Bandwidth is not synchronized after successful relay.
  • When relaying a wifi with Chinese name, the page displaying the relayed wifi name is abnormal.
  • After successful relaying, the MAC address is not correct when checking the connection rate in the background.
  • Fix the problem of interface setting failure when switching to high frequency channel.
  • Occasionally 2.4G guest WiFi is not available.
  • WiFi name is 32 characters and ends with English special character, background ESSID shows unknown.
  • After turning on all WiFi and relaying 5G WiFi, turn off 5G WiFi of the device, the relay keeps disconnecting, and the front-end does not show relay status.
  • When there is no network on the parent, kmwan detects IPv6 abnormally.
  • Fix the problem that executing firstboot -y reboot does not reboot automatically after turning on tailscale.
  • PPPOE dialing with VLANID when LAN1 is switched to WAN, then switch to WDS mode, and then switch back to routing mode, the VLANID of PPPOE needs to be re-entered to dial successfully.
  • The secondwan function on the page adds a prompt corresponding to the WAN and LAN1 physical network ports.
4.5.11 2024-06-03
SHA256: 94e111d0667e6718... 🔗 share
Release notes

V4.5.11

Overview

This is the initial firmware release for the b3000.

This release is available for the following models:
GL-B3000

4.7.15 2025-08-01
SHA256: d948080234667cf6... 🔗 share
Release notes

V4.7.15

Overview

This version includes adjustments to enhance device security.

New Features

  • Added a global SSH toggle.

Optimization

  • Added a user privacy policy statement to the initialization wizard page.
  • Added a security warning when WiFi security is set to OPEN.
  • Optimized the network abnormal traffic protection mechanism, adding flood protection for ICMP and other protocols.
  • LuCI functionality is no longer pre-installed; users can install LuCI with one click on the advanced settings page.
  • Optimized Nginx log management, adding login and configuration change logs. Logs are automatically synchronized to Flash upon reboot.

GL-BE10000 Slate 7 Pro be10000

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.4 2026-04-21
SHA256: 7d54205721c43f57... 🔗 share
Release notes

V4.8.4

Overview

This is initial firmware.

GL-BE3600 Slate 7 be3600

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.3 2026-02-07
SHA256: 90b34ad1c74b666c... 🔗 share
Release notes

V4.8.3

Overview

This version mainly fixed some known bugs.

Optimization

  • Replaced NTPD with Chrony, which supports the NTS protocol.
  • Optimized the Repeater's detection logic for Captive Portal to be compatible with and identify more authentication pages in different formats.
  • Optimized the switching logic of the Repeater: when the internet is already connected, the repeater will not scan for available networks to ensure wireless communication quality.
  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018.
  • Merge the patch related to CVE-2025-62526.
  • Fixed the issue of iPhone 16 series failed to connect to MLO network.
  • Fixed the issue where the WireGuard server cannot access the LAN IP of the WireGuard client without enabling SNAT.
  • Fixed the issue where some iOS browsers displayed VPN Dashboard abnormally
  • Fixed the issue where changing the failover priority would cause abnormal IPv6 internet access when both Multi-WAN and IPv6 are enabled.
  • Fixed the issue where the IPv6 DNS was mistakenly pointed to Cloudflare (2606:4700:4700:1001) instead of the server's tunnel IP when the client connected to the OpenVPN server.
  • Fixed the issue where DNS requests from clients that do not comply with VPN rules still reach AdGuard Home when All Other Traffic is disabled.
  • Removed duplicate OpenDNS service provider in the options of Manual DNS settings.
  • Fixed the issue where the WebDAV certificate address was replaced with the guest network address after modifying the latter, resulting in abnormal connections for LAN side devices.
  • Fixed the issue where the port check function could not distinguish protocols in VPN server mode.
  • Fixed the issue of no failure reminder when WireGuard port conflicts occurred.
  • Fixed the issue where the exclusion list rule set did not take effect when two VPN tunnels were enabled.
4.8.1 2025-08-19
SHA256: 5ee712f300ee10f0... 🔗 share
Release notes

V4.8.1

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance, allowing support for enabling multiple VPN clients at the same time.
  • Added VPN composite policy, allowing traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only when the VPN policy is based on MAC.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added support for HTTPS in RTTY.
  • Added a one-click option to send logs to technical support.
  • Added support for IPv6 in VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized toggle switch functionality to support Repeater, and Wi-Fi.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.
4.7.3 2025-06-03
SHA256: 8bf0a97817b41cdf... 🔗 share
Release notes

V4.7.3

Overview

This version primarily addresses some software bugs.

Bug Fixes

  • Fixed the problem that the LCD Display Schedule could not be used due to the upgrade of reserved configuration.
4.7.2 2025-05-29
SHA256: 82982408bb4ca0c2... 🔗 share
Release notes

V4.7.2

Overview

This version adds the new features of display managment and fixes some software bugs.

New Features

  • Upgraded the system from 32-bit to 64-bit.
  • Added software acceleration feature to optimize tethering speed.
  • Added a display management feature to set the screen content and lock screen password.

Optimization

  • Improved the the speed of OpenVPN and WireGuard.
  • Enhanced the user experience by adding prompts related to USB device interactions.
  • Improved the screen usage experience.

Bug Fixes

  • Fixed the memory leak issue that occurred under specific conditions.
  • Fixed an issue where enabling both AdGuard Home and the block non-VPN traffic option caused online upgrade detection to fail.
  • Fixed a VPN leak issue that occurred when both the WireGuard client and IPv6 were enabled.
  • Fixed a DNS leak issue that occurred under certain conditions when both VPN and AdGuard Home were enabled.
  • Fixed an issue in VPN policy mode where using destination domain or IP-based rules allowed guest network clients to access the main network clients.
  • Fixed an issue in TAP-S2S mode where downstream clients could not obtain an IP address after a successful OpenVPN connection.
  • Fixed an issue where the WAN interface could not obtain an IPv6 address after the WAN and LAN ports were swapped.
  • Fixed an issue where offline clients were displayed as local clients when they shared the same IP address.
  • Fixed an issue where the default sorting for clients was not applied.
  • Fixed an issue where modifying the Wi-Fi configuration on the cloud platform would automatically alter the Wi-Fi SSID visibility.
  • Fixed an issue where the firmware compilation time was incorrectly displayed on the cloud platform.
  • Fixed an issue where AP isolation failed to work after network acceleration was disabled in certain scenarios.
  • Fixed an issue where obtaining an IP address was too slow during a repeater connection.
  • Fixed an issue where retaining the configuration after disconnecting the repeater caused Wi-Fi configuration errors during an upgrade.
  • Fixed an issue where the network status on the page was incorrectly displayed before portal authentication was completed.
  • Fixed an issue where an abnormal power-off could cause the device to fail to start in rare cases.
  • Fixed an issue where PPPoE dial-up failed under certain conditions.
4.7.1 2025-03-07
SHA256: df2acba0a17267b9... 🔗 share
Release notes

V4.7.1

Overview

This version mainly adds some new features, fixes some problems and optimises the interface interaction to improve the user experience.

Synchronize Updated Model

Slate 7(GL-BE3600)

New Features

  • Added the function of switching service providers on the screen.
  • Added the function of displaying IP addresses in AP/WDS/Extender mode on the screen.
  • Added the option to skip the operation wizard on the screen.

Bug Fixes

  • Fixed the abnormal networking problem of Tethering on some mobile phones.
  • Fixed the problem of displaying incorrect time zones on some time zones.
  • Fixed the problem that changing the WAN port MAC address would cause the network to restart.
4.9.0 beta4 build 1012 2026-05-16
SHA256: 87fce2db071284d2... 🔗 share
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-16: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.9.0 beta4 build 1007 2026-04-24
SHA256: 27d2ad7ea5156bea...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.9.0 beta3 build 995 2026-04-17
SHA256: 978d3ef1bf038a04...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • Optimized the configuration retention during upgrades to preserve user-installed plugins.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.9.0 beta2 build 990 2026-04-14
SHA256: a8d4fc862cc63392...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, all existing configurations for this feature will not be retained during the upgrade. You will need to reconfigure the settings after the update.
  • Due to the implementation of multi-select configuration and intra-tunnel failover in VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch in all tunnels will be enabled by default.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent Quality of Service (QoS).
  • Added SQM (Smart Queue Management) function to intelligently optimize network queues, reduce latency and lag, and improve the overall internet experience.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option for enabling/disabling specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, destination IP address, source IP address, and port number.
  • Added support for running Tailscale as an exit node and an IP masquerading option.
  • Added the feature of disabling automatic detection and canceling upgrade for firmware online upgrade.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Address Reservation supports setting a Hostname.
  • Added support for the AmneziaWG obfuscation protocol.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, enhancing the user experience
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • Optimized the configuration retention during upgrades to preserve user-installed plugins.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, Multi-WAN IPv6 connection state tracking is now automatically activated.
4.9.0 beta1 build 989 2026-04-11
SHA256: c87520d36727eed5...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, all existing configurations for this feature will not be retained during the upgrade. You will need to reconfigure the settings after the update.
  • Due to the implementation of multi-select configuration and intra-tunnel failover in VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch in all tunnels will be enabled by default.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent Quality of Service (QoS).
  • Added SQM (Smart Queue Management) function to intelligently optimize network queues, reduce latency and lag, and improve the overall internet experience.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option for enabling/disabling specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, destination IP address, source IP address, and port number.
  • Added support for running Tailscale as an exit node and an IP masquerading option.
  • Added the feature of disabling automatic detection and canceling upgrade for firmware online upgrade.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Address Reservation supports setting a Hostname.
  • Added support for the AmneziaWG obfuscation protocol.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, enhancing the user experience
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Optimized the configuration retention during upgrades to preserve user-installed plugins.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, Multi-WAN IPv6 connection state tracking is now automatically activated.

GL-BE6500 Flint 3e be6500

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.8 2026-06-06
SHA256: 54c2e80d709de986... 🔗 share
Release notes

V4.8.8

Overview

This version fixes some bugs.

4.8.7 2026-01-12
SHA256: 12344a4748d9739f... 🔗 share
Release notes

V4.8.7

Overview

This version fixes some bugs.

4.8.6 2025-12-29
SHA256: 6a1c23dd31f8a422... 🔗 share
Release notes

V4.8.6

Overview

This version fixes some bugs.

4.8.5 2025-11-12
SHA256: 58f8381b84ac4c5d... 🔗 share
Release notes

V4.8.5

Overview

This version fixes bugs related to repeater and IPv6.

Bug Fixes

  • Fixed the issue of network instability after the repeater was disconnected.
  • Fixed some bugs about IPv6
4.8.4 2025-10-17
SHA256: 6bf576bb49f31bc1... 🔗 share
Release notes

V4.8.4

Supported Models

GL-BE6500

4.8.8 2026-03-30
SHA256: 0ed8264a564ea428... 🔗 share
Release notes

V4.8.8

Overview

This version mainly fixed some known bugs.

GL-BE9300 Flint 3 be9300

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.9.0 2026-05-21
SHA256: edf306a312c85c44... 🔗 share
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
  • Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.8.4 2026-02-07
SHA256: 53e7c911bc6b6100... 🔗 share
Release notes

V4.8.4

Overview

This version improves the interface interaction and fixes some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.
4.8.3 2025-11-27
SHA256: 471b39ad8d64352b... 🔗 share
Release notes

V4.8.3

Overview

This version mainly fixed some known bugs.

Optimization

  • Replaced NTPD with Chrony, which supports the NTS protocol.
  • Optimized the Repeater's detection logic of Captive Portal to be compatible with identifying more authentication pages in different formats.
  • Optimized the switching logic of the Repeater; when the internet is already connected, the repeater will not scan for available networks to ensure wireless communication quality.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018.
  • Merge the patch related to CVE-2025-62526.
  • Fixed iPhone 16 series connection to MLO network failed.
  • Fixed the issue where WireGuard server cannot communicate with the LAN side of the router (WireGuard client) without enabling SNAT.
  • Fixed the issue of abnormal VPN Dashboard display in some IOS browsers.
  • Fixed the issue of using IPv6 to access the internet after changing the failover priority when using Multi WAN with IPv6 enabled.
  • Fixed an issue in OpenVPN Server mode where the client's IPv6 DNS was incorrectly pointed to Cloudflare (2606:4700:4700:1001) instead of the server's tunnel IP after connection.
  • Fixed the issue where DNS requests still reach AdGuard Home for clients not within VPN rules when All Other Traffic is disabled.
  • Fixed duplicate OpenDNS service provider in the options of Manual DNS settings.
  • Fixed the issue of LAN side device connection caused by the address of the WebMAV certificate being changed to the address of the guest network after modifying the guest network address.
  • Fixed the issue where the port check function could not distinguish protocols in VPN server mode.
  • Fixed the issue of no failure reminder when WireGuard port conflicts occurred.
  • Fixed the issue where two VPN tunnels were opened and exclusion list rules were set, but the rules did not take effect.
4.8.1 2025-08-20
SHA256: 24f79a3f0b0858fd... 🔗 share
Release notes

V4.8.1

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance, allowing support for enabling multiple VPN clients at the same time.
  • Added VPN composite policy, allowing traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only when the VPN policy is based on MAC.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added support for HTTPS in RTTY.
  • Added a one-click option to send logs to technical support.
  • Added support for IPv6 in VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.
4.7.14 2025-07-21
SHA256: 29a072ff47acbe74... 🔗 share
Release notes

V4.7.14

Overview

This version primarily addresses certain MLO-related issues and improves the stability of MLO Wi-Fi.

Improvement

  • Fixed issues related to MLO and 6 GHz configuration.
  • Resolved an issue where DLNA functionality would fail after rebooting with a USB drive inserted.
  • Fixed a problem in the network setup wizard where logging into NordVPN would incorrectly display the connection status and prevent the VPN from being disabled.
4.7.11 2025-05-29
SHA256: ce6024fc7315c851... 🔗 share
Release notes

V4.7.11

Overview

This version fixes bugs related to HTTPS implementations.

Bug Fixes

  • Fixed an issue where the cloud platform malfunctioned after enforcing HTTPS.
4.9.0 release5 build 1022 2026-05-16
Firmware (.bin) archived
SHA256: edf306a312c85c44... 🔗 share
📝 Removed from GL.iNet download site on 2026-05-21
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
  • Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.9.0 release4 build 1020 2026-05-13
SHA256: e7bb392f55795e33...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.9.0 beta4 build 1007 2026-04-24
SHA256: 96f6db466911a823...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.9.0 beta3 build 995 2026-04-17
SHA256: db5baafcc2f189b5...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • Optimized the configuration retention during upgrades to preserve user-installed plugins.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.9.0 beta2 build 990 2026-04-14
SHA256: 92b43202efbd3b34...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, all existing configurations for this feature will not be retained during the upgrade. You will need to reconfigure the settings after the update.
  • Due to the implementation of multi-select configuration and intra-tunnel failover in VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch in all tunnels will be enabled by default.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent Quality of Service (QoS).
  • Added SQM (Smart Queue Management) function to intelligently optimize network queues, reduce latency and lag, and improve the overall internet experience.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option for enabling/disabling specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, destination IP address, source IP address, and port number.
  • Added support for running Tailscale as an exit node and an IP masquerading option.
  • Added the feature of disabling automatic detection and canceling upgrade for firmware online upgrade.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Address Reservation supports setting a Hostname.
  • Added support for the AmneziaWG obfuscation protocol.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, enhancing the user experience
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • Optimized the configuration retention during upgrades to preserve user-installed plugins.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, Multi-WAN IPv6 connection state tracking is now automatically activated.
4.9.0 beta1 build 989 2026-04-11
SHA256: fd3ee00e5187a7d8...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, all existing configurations for this feature will not be retained during the upgrade. You will need to reconfigure the settings after the update.
  • Due to the implementation of multi-select configuration and intra-tunnel failover in VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch in all tunnels will be enabled by default.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent Quality of Service (QoS).
  • Added SQM (Smart Queue Management) function to intelligently optimize network queues, reduce latency and lag, and improve the overall internet experience.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option for enabling/disabling specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, destination IP address, source IP address, and port number.
  • Added support for running Tailscale as an exit node and an IP masquerading option.
  • Added the feature of disabling automatic detection and canceling upgrade for firmware online upgrade.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Address Reservation supports setting a Hostname.
  • Added support for the AmneziaWG obfuscation protocol.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, enhancing the user experience
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Optimized the configuration retention during upgrades to preserve user-installed plugins.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, Multi-WAN IPv6 connection state tracking is now automatically activated.
4.8.99 2026-01-21
Firmware (.bin) archived
SHA256: bec6bce67222308d... 🔗 share
📝 Removed from GL.iNet download site on 2026-04-21
Release notes

V4.8.99

New Features

  • Add Data Statistics functionality to monitor router traffic usage.
  • Add Content Protection functionality to block dangerous and malicious websites.
  • Add QoS functionality to optimize bandwidth usage during network congestion.
  • Preinstall SQM functionality to optimize network experience through intelligent queuing.
  • Add VPN Obfuscation functionality to enhance the encrypted transmission security and privacy of VPN networks.
4.8.2 2025-08-29
Firmware (.bin) archived
SHA256: 921c282f872c03ff... 🔗 share
📝 Removed from GL.iNet download site on 2026-04-21
Release notes

V4.8.2

Overview

This version mainly fixed some known bugs.

Bug Fixes

  • Fixed the compatibility issue with Virgin Hub 5.

GL-E5800 Mudi 7 e5800

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.5 2026-06-03
SHA256: 39f34023fa02c0de... 🔗 share
Release notes

V4.8.5

Overview

This version fixes some issues to improve the user experience.

Bug Fixes

  • Fixed an issue where dial-up failed due to slow network registrations on certain ISP networks.
4.8.4 2026-05-29
SHA256: d9254b85f0d00f05... 🔗 share
Release notes

V4.8.4

Overview

This version fixes some issues and includes optimizations to improve the user experience.

Optimization

  • Optimized the automatic reconnection mechanism for repeater in AC+AP or mesh scenarios to speed up reconnection.
  • Adjusted the battery temperature detection to improve battery level display.
  • Optimized the display of locked carrier names.
  • Optimized the country code information in the database.
  • Optimized the data usage statistics feature.

Bug Fixes

  • Fixed an issue where disabling the repeater occasionally failed when continuously disabling it on the touchscreen.
  • Fixed an issue where the OTA upgrade popup was missing on the touchscreen home page in AP mode and Extender mode.
  • Fixed an issue where SMS functionality became unavailable after repeatedly switching network types and SIM cards.
  • Fixed an issue where manually configured APN was not correctly displayed on the SIM card details page when using a MobileX SIM card.
  • Fixed an issue where the Mudi 7 could not scan nearby Wi-Fi networks when the surrounding Wi-Fi had a special OUI type (0050f2).
  • Fixed the issue of unstable cellular network caused by incomplete support for segment characteristics of partial base stations in Europe.
4.8.3 2026-04-20
SHA256: dc1656bac0ae11c7... 🔗 share
Release notes

V4.8.3

Overview

This version mainly fixes abnormal internet dialing issues for specific carriers.

Bug Fixes

  • Fixed an issue where abnormal dialing with Verizon carrier.
4.8.2 2026-04-09
SHA256: 0196e88ff9024f5a... 🔗 share
Release notes

V4.8.2

Overview

This version fixes some issues to improve the user experience.

Optimization

  • Optimized high-temperature battery charging to speed up charging in certain temperature ranges.
  • Optimized repeater status display on touchscreen.

Bug Fixes

  • Fixed an issue where locking the NR base station on SIM2 would fail when two SIM cards from different carriers were inserted.
  • Fixed an issue where unlocking would fail on eSIM after switching from SIM2 with a successful NR base station locking.
  • Fixed an issue where some PD adapters could not charge.
  • Fixed an issue where the top status bar on the touchscreen would not display properly after a failed online upgrade via the touchscreen.
  • Fixed an issue where downstream devices of Mudi 7 failed to obtain an IP address when Mudi 7 was connecting to certain MTK chips Wi-Fi networks in Extender mode.
4.8.1 2026-03-16
SHA256: 8e6e9d477333d95e... 🔗 share
Release notes

V4.8.1

Overview

This version introduces a new feature and fixes some issues to improve the user experience.

New Features

  • Added online update support for the touchscreen.

Optimization

  • Optimize battery level recognition and charging after hot-swapping the battery at low battery level.

Bug Fixes

  • Fixed an issue where verification was still required after successful portal authentication.
  • Fixed an issue where OpenVPN failed to connect after a power cycle when connected in TAP‑S2S mode.
  • Fixed an issue where SMS messages in Greek and Italian were displayed as garbled characters.

GL-E750/GL-E750V2 Mudi e750

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.26 2025-04-08
SHA256: edf1ba09412592e0... SHA256: d13bdcc978212faf... 🔗 share
Release notes

V4.3.26

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.19 2024-09-06
SHA256: 1b5a5b785335e66e... SHA256: f5c451f14a9b7805... 🔗 share
Release notes

V4.3.19

Overview

This release mainly adds new features and fixes bugs.

Supported models

GL-E750/GL-E750v2.

New features

  • Added VSIM functionality(For new device).
  • Introduce automatic dialing function for Webbing card.
  • Implemented ESIM support.
  • Added compatibility for the EM12G Modem module.

BUG fix

  • Resolved an issue where MoResolved an issue where Modem QMI protocol dialing and PAP/CHAP authentication could fail.
  • Fixed the issue where Modem IPV6 dialing probabilistically failed to obtain an IPV6 address.
  • Addressed several known security vulnerabilities.
4.3.18 2024-08-23
SHA256: b08ef453337b8ff6... SHA256: 32f502071b18c5f0... 🔗 share
Release notes

V4.3.18

Overview

This version fixes some security vulnerabilities.

Supported models

Slate (GL-AR750S), Creta (GL-AR750), Mudi (GL-E750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300).

4.3.17 2024-06-07
SHA256: 17be4823da02cdc9... SHA256: f2efd1534e6b9f62... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.12 2024-04-10
SHA256: 34a06fdafc0d6133... SHA256: 4ab5682181365381... 🔗 share
Release notes

V4.3.12

Overview

This version mainly includes bug fixes, and security vulnerability resolutions, as shown below.

Bug fixes

  • Fixed E750V2 problem with abnormal display caused by modem name being too long.
  • Fixed the error in determining whether the ep06 SMS function is available.
  • Fixed some known vulnerabilities.
  • Fixed channel exception when 5g wifi country is DE.
4.3.9 2024-02-02
SHA256: 5df28bb4dae518f9... SHA256: 6a8e43907b5226ed... 🔗 share
Release notes

BUG fix

  • Fix crash when downloading large files on 3G dial-up.
  • Fix the black screen issue when v1 custom text page restarts.
  • Fix the problem of abnormal display of operator name.
  • Optimize cloud process memory usage.
  • Fix the problem that openvpn cannot connect when multiple Wan cables are not connected to the network.
  • Fix the abnormal problem of accessing https site through s2s tunnel.
  • Fix the problem that lower-level devices in ipv6 passthrough mode cannot obtain ipv6 addresses.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.3.8 2023-09-19
SHA256: 5d686d0063b9f6f9... SHA256: 9e0b711e317ed2f6... 🔗 share
Release notes

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (E750).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and Battery condition.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS feature.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fi with the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.
  • Optimized the memory consumption during the tor connection process, causing the device to freeze.
4.8.5 2026-05-21
SHA256: 476dc6e1deea2536... SHA256: 799e73e000c3ec5d... 🔗 share
Release notes

V4.8.5

Overview

This version mainly fixed some known bugs. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • Fixed modem dial-up issues.
  • Fixed abnormal log printing issues related to the modem.
  • Fixed the issue where OLED did not display VPN connection status.
  • Fixed the issue where Cell Info was not fully displayed when EM060K module used multi-band carrier aggregation for networking.
  • Fixed SMS display issues.
  • 2026-05-21: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.8.4 2026-03-30
SHA256: 4f33c3f2d6e42c22... SHA256: f3ad765de176b3c5... 🔗 share
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Bug Fixes

  • Fixed modem dial-up issues.
  • Fixed abnormal log printing issues related to the modem.
  • Fixed the issue there OLED did not display VPN connection status.
  • Fixed the issue where Cell Info was not fully displayed when EM060K module used multi-band carrier aggregation for networking.
  • Fixed SMS display issues.
4.8.3 2025-09-30
SHA256: ee2f06fcfef7d26c... SHA256: 29df2f74cac18b4c... 🔗 share
Release notes

V4.8.3

Cautions

The OpenWRT version has been upgraded. Please do NOT keep settings when downgrading to an earlier version. Please backup your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized toggle switch functionality to support Repeater, Wi-Fi and LED light control.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the device binding functionality of the GoodCloud platform.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
  • Fixed when configuring the VPN domain name policy, the domain names in the list cannot be resolved properly
  • Fixed OLED cannot accurately display the VPN status
3.217 2023-05-08
SHA256: c81f709b4dadd395... SHA256: 5dab717c1b418b5d... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (MIFI,X750,E750,XE300,XE300)
  2. Based on QSDK11 (AP1300)

Important bugfix

  1. Fix account error for SMTP settings.
3.216 2023-03-21
SHA256: 92f90ca5c674f954... SHA256: 99c5597eddf4d71c... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

GL-MiFi mifi

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
3.217 2023-05-08
SHA256: d51a72d2263189e3... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (MIFI,X750,E750,XE300,XE300)
  2. Based on QSDK11 (AP1300)

Important bugfix

  1. Fix account error for SMTP settings.
3.216 2023-03-21
SHA256: 7e203fd78071b428... 🔗 share
Release notes

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

GL-MT1300 Beryl mt1300

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.25 2025-03-31
SHA256: e906a213ed66027b... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.19 2024-08-23
SHA256: 258f29fb043f772c... 🔗 share
Release notes

V4.3.19

Overview

This version fixes some security vulnerabilities.

Supported models

Beryl (GL-MT1300), Spitz (GL-X750), Opal (GL-SFT1200).

4.3.18 2024-08-03
SHA256: 1a5b02ba907d33e8... 🔗 share
Release notes

V4.3.18

Overview

This version introduces new SIM APN support, alongside various bug fixes and security enhancements.

Supported Models

Beryl(GL-MT1300), Spitz(GL-X750V2), Opal(GL-SFT1200).

New Features

  • Added APN support for Webbing SIM cards (wbdata)(GL-X750V2).

Bug Fixes

  • Fixed the issue where the device fails to connect to the network via QMI or QCM protocols when a telecom card is inserted and IPv6 is enabled.
  • Fixed the issue of dnscrypt generating unnecessary logs on SFT1200 devices.
  • Fixed the misidentification of LAN port speed on SFT1200 devices.
  • Fixed the issue where the default luci page of SFT1200 only supports English configurations, excluding Chinese.
  • Fixed the generation of unnecessary netclash logs during the startup process.
  • Fixed dial-up failures on the modem during the dialing process when using QMI protocol, manually setting APN, and selecting PAP/CHAP authentication.
  • Fixed the issue that under European (DE) country code, there will be a high band channel (149-161), and the channel display is wrong when 20MHz bandwidth is set.
  • Fixed the problem of 2.4GHz channel display error after switching to Japan country code in luci page.
  • Fixed the issue that when GL-MT1300 long press Reset for 4-7 seconds to switch routing mode, the br-lan interface is not working.
  • Fixed the issue that the GL-X750V2 cannot ping IPV6 web site after switching IPV6 mode.
4.3.17 2024-06-07
SHA256: 29a31700a5b20d30... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.11 2024-03-20
SHA256: 01413237e627c653... 🔗 share
Release notes

V4.3.11

Overview

This firmware release provides optimizations, bug fixes, and fixes for security vulnerabilities.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added language support for Korean.
  • (Only available on GL-X750) Added some software packages: kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs.

Bug fixes

  • Fixed an issue with GL-MT300N-V2 where the dip switch and the UI display were reversed.
  • Fixed an issue with GL-MT300N-V2 where wireless terminals could not obtain an address after successfully switching to the Extend and WDS modes.
  • Fixed an issue where two routers acting as the VPN server and the VPN client respectively could not automatically reconnect after disconnection due to network volatility.
  • Fixed an issue where client devices connected through an ethernet cable would not automatically reconnect after the LAN IP address was modified.
  • Fixed a conflicted that occurred with GL-SFT1200 between PPPoE protocol with VLAN ID and hardware acceleration.
  • Fixed an error that happened when a device using PPPoE protocol first switched to the Extender mode and then restored the Route mode.
  • Fixed various known vulnerabilities.
4.3.10 2024-02-02
SHA256: 19a767337ea24833... 🔗 share
Release notes

V4.3.10

Overview

This version mainly includes optimizations, bug fixes, and security vulnerability resolutions, as shown below.

This release is available for the following models:
GL-AR300M Shadow
GL-AR300M16 Shadow
GL-AR750 Creta
GL-AR750S-EXT Slate
GL-B1300 Convexa-B
GL-MT300N-V2 Mango
GL-MT1300 Beryl

Bug fixes

  • Fixed deadlock issue in mwan3.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.3.7 2023-09-13
SHA256: 64009e6e05b703ca... 🔗 share
Release notes

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS faeture.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fiwith the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.

BUG fix

  • Fixed the TTL settings not taking effect when fw4 is used.
4.3.26 beta1 build 455 2026-05-29
SHA256: 0ac93280b2055d94... 🔗 share
Release notes

V4.3.26

Overview

This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • 2026-05-28: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.3.26 beta1 build 454 2026-05-25
SHA256: 42959a21cd6658d7...
Release notes

V4.3.26

Overview

This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • 2026-05-19: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
3.216 2023-03-21
SHA256: 8e271b40be1e4983... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

GL-MT2500/GL-MT2500A Brume 2 mt2500

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.7.4 2025-03-28
SHA256: 3de78f88a2cc204c... 🔗 share
Release notes

V4.7.4

Overview

This version fixes some security vulnerabilities and other bugs.

Bug Fixes

  • Fixed the issue where the failed VPN policy subscription URL request would display an unknown error.
  • Fixed the issue where turning off 'Override DNS Settings of All Clients' would not take effect after enabling AdGuard Home or VPN Client.
  • Fixed the issue where DDNS testing failed to display the WAN address of Ethernet 2.
  • Fixed an issue where no error message was displayed when entering an incorrect old password, while changing the administrator password.
  • Fixed the issue where manually adding a WireGuard Client configuration would incorrectly prompt the error message.
  • Fixed the issue where modifying the administrator password did not log out the current LuCI session.
  • Fixed the issue where the AzireVPN login password containing special characters, such as '$', would incorrectly trigger an 'invalid login info' error message.
  • Fixed the issue where the client name containing a comma prevented address retrieval.
  • Fixed the issue where the GL.iNet APP could not customize client types.
  • Fixed the issue where network storage could not share directories containing special characters.
  • Fixed the issue where Wi-Fi 5G downlink rate decreased after the client was connected for a period of time.
  • Fixed the issue where turning on the 'Camouflage' mode would still fail to pass the portal authentication.
  • Fixed the issue where switching from DHCPv6 to PPPoEv6 prevented the downstream devices from accessing the internet.
  • Fixed the issue where switching to WDS mode, after enabling AP isolation, would cause address acquisition failure.
  • Fixed the issue where the WireGuard Client name field would close automatically when tapping outside the input area.
4.7.0 2024-12-05
SHA256: 201ec244f73c6f49... 🔗 share
Release notes

V4.7.0

Overview

This version introduces several new features and enhancements that improve the interface interaction for overall user experience.

Synchronize Updated Models

Beryl AX (GL-MT3000), Brume 2 (GL-MT2500), Flint 2 (GL-MT6000).

New Features

  • Added device initialization wizard, including settings for administrator and WiFi password, networking connection, VPN and other core functionalities.
  • Added AstroWarp mode (Beta), allowing you to create your own network using aggregated connections and cloud gateways for a high-speed, stable network experience.
  • Added cloud account login functionality, supporting device binding to the cloud from the firmware web page.
  • Added domain name list subscription feature, supporting VPN policies and parental control through URL subscriptions for online domain name or IP list.
  • Added support for Control D DNS.
  • Added AP Isolation function.
  • Added Luci Access Restriction function.
  • Added USB port protocol conversion function, allowing downgrading to use USB 2.0.
  • Added Network Port Management page, supporting scheduled and reboot of automatic updates for Ethernet MAC, WAN/LAN port switching, and displaying network port negotiation rates.
  • Added support for NordVPN, PIA, Surfshark, Hideme, IPVanish WireGuard VPN services, along with AzireVPN registration functionality.

Optimization

  • Optimized the process for manually adding the WireGuard client configuration files and supporting automatic key generation.
  • Optimized the process of configuring vendor profiles for VPN clients.
  • Optimized repeater random MAC settings, supporting scheduled and reboot of automatic updates for repeater MAC.
  • Optimized the detection process for multi-WAN load network status.
  • Optimized OpenVPN Client functionality, allowing modification of configuration file names.
  • Optimized the page names in the web management panel so that the router's hostname is displayed in the browser tab.
  • Optimized the design of interface error messages and interactive elements like input dropdown lists.
  • Upgraded AdGuard Home to version 0.107.52.
  • Upgraded Tor to version 0.4.8.9.
4.6.8 2024-10-17
SHA256: 7d28e9f3520412a5... 🔗 share
Release notes

V4.6.8

Overview

This version mainly focuses on fixing a few known bugs.

Synchronized Updated Models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

Improvement

  • Upgrade AdGuard Home version to v0.107.52.

Bug Fixes

  • Fixed the issue where, after enabling the VPN client and using Global Proxy, enabling AdGuard Home to handle client requests resulted in only localhots 127.0.0.1 appearing in the client list on the settings page.
  • Fixed the issue that TCP port can be probed when WireGuard Server is enabled.
  • Fixed the issue where the 5G wireless disappeared after the device relayed an upstream device with a 5G channel set to 20M dfs.
  • Fixed the issue that resulted in unusual log messages.
  • Fixed the issue where the router's own DNS requests always went through the dnsmasq proxy after switching DNS settings on the page.
4.6.4 2024-09-04
SHA256: ceddb30e95c569d5... 🔗 share
Release notes

V4.6.4

Overview

This version mainly focuses on fixing a few known bugs and fixes some security vulnerabilities to enhance the user experience.

Supported Models

GL-AX1800, GL-AXT1800, GL-MT2500/GL-MT2500A, GL-MT3000, GL-MT6000.

Improvement

  • Updated WiFi driver(MT3000).

Bug Fixes

  • Fixed an issue with DNS leaks when upgrading from version 4.5.x reserved configurations to 4.6.x with VPN connected.
  • Fixed the issue that when the 5G main network is not a DFS channel, the 5G main network page will be opened again with a prompt of about 3s for DFS channel availability detection.
  • Fixed a relay scan timeout issue when the WiFi was configured with DFS channels.
  • Fixed the issue where the relay icon did not turn gray when disconnecting the relay connection while the internet connection mode was set to relay and wired.
  • Fixed the issue where language packs were not retained after upgrading with preserved configuration.
  • Fixed the issue where PC WebDAV access would show no data, after enabling WebDAV, inserting a USB drive, and rebooting.
  • Fixed the issue where RTTY-WEB remote access encountered relay scan errors and failed to relay.
  • Fixed a crash of the device's WiFi driver when connecting with a D-Link DWA-192 AC1900 network adapter to 2.4G WiFi.
  • Corrected an issue where adding and applying any custom rule in parental control had no effect on Google Chrome.
  • Fixed an issue where trunks were configured with static IPs, and the trunks showed up as connected even though the trunks were disconnected.
  • Fixed the issue of DNS leakage when VPN Client and DNS encryption are enabled.
  • Corrected a problem where switching internet connection modes did not update the IP address in DDNS resolution.
  • Fixed an issue where videos and images on the USB drive could not be accessed after inserting a USB drive, enabling DLNA, and soft resetting the device.
  • Resolved a DNS leak issue when switching VPN policy from global proxy to IP/domain-based mode.
  • Fixed the issue that the client's hostname was reported to the relay's superior after the relay set a random MAC.
  • Fixed the issue that the WAN port does not show IPv6 address when connecting to a VPN client and then enabling IPv6.
  • Addressed a program crash caused by relay scanning when no other APs were nearby.
  • Corrected a crash caused by wireless scanning of SSIDs containing carriage return characters.
  • Fixed the issue where accessing the device management page using an IPv6 address displayed incorrect MAC cloning information for Ethernet and relay.
  • Fixed the issue where the WebDAV function did not work properly when using an account or password with a length of 64-bit characters.
  • Fixed the issue that after pulling Mullvad VPN configuration, when the corresponding Public Key is deleted from the Mullvad website and the configuration is pulled again, the IP address in the pulled configuration changes to 'The'.
  • Resolved the issue of relay scanning crashing when IBSS exists in the surrounding area.
  • Fixed the issue where firewall rules would occasionally disappear after rebooting the device following a connection to wgclient.
  • Fixed the issue where dip switch is bound to wireguard client, the device turns on ovpn client, and restarting the device causes vpn policy to fail.
  • Fixed the issue where the killswitch failed to work when the DNS service was proxied by the AdGuard program or an encrypted DNS program, and the VPN was in a connected state.
4.6.2 2024-06-28
SHA256: c9ad8ac3fa189cfd... 🔗 share
Release notes

V4.6.2

Overview

This version mainly provides the following improvements:

  • Improved the user experience with the repeater feature. Resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Improved the display of IPv6 addresses, and added support for customization of the interface language packs.

Supported models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

New features

  • Added the Login Mode for Public Hotspots and the Camouflage Mode. This resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Added the option to use a randomized BSSID to prevent devices from being traced by BSSID.
  • Added the UI language pack management feature. This allows adding additional language packs and subscribing to language pack updates.
  • Added an option to choose whether the VPN interface uses manually configured DNS. This allows using the VPN's DNS servers, if Encrypted DNS or AdGuard Home is enabled.
  • Added support for port range forwarding and port forwarding rule prioritization options.
  • Added TTL, HL, and MTU options for each interface.
  • Added support for connecting to Wi-Fi via QR code.

Improvements

  • Optimized the repeater feature to enhance performance and user experience. Added support for configuring MAC address for SSIDs individually.
  • Optimized the display of IPv6 address on the Internet page and the Client page.
  • Optimized the MAC address setting logic to support cloning or setting random MAC addresses for each interface.
  • Optimized the status display on the Tethering interface to make a clear distinction between 'disabled' and 'enabled but no device'.
  • Optimized the port forwarding feature. It now has its own page within the admin panel and can function simultaneously as DMZ. The port opening (previously on the Firewall page) has been moved to the Security page.
  • Optimized the logic of jumping after LAN IP is modified so that users do not need to sign in again.
  • Optimized the logic of guest network enabling. If guest Wi-Fi is disabled, guest network will also be disabled.
  • Optimized the logic of toggle switches. When rebooting a device, the enabling status of corresponding services (such as VPN) will be set according to the status of the toggle switch.
  • Removed the length restriction on mobile phone number in SMS sending and forwarding.
  • Removed the option 'Force 20MHz Bandwidth For 2.4G' from the Repeater settings.
  • Upgraded AdGuard Home to version 0.107.46.

Bug fixes

  • Fixed an issue where reserved IP addresses were incorrectly sorted by IP if the IP address range was large.
  • Fixed instances where abnormal issues would occur during firmware grade when “keep settings” was selected during IPv6 mode.
  • Fixed an issue where the reset feature would not work when Tailscale was enabled.
  • Fixed an issue where parental controls would not properly resolve domain names using capital letters (e.g., WWW.GOOGLE.COM).
  • Fixed an issue where manually configured routes would not work in some cases when the VPN client was in custom routing proxy mode.
  • Fixed an issue where the cellular interface would incorrectly determine the internet status of the IPv6 protocol.
  • Fixed an issue where the manual DNS server address in the DNS interface would be invalid after disabling AdGuard Home.
  • Fixed an issue where the imported WireGuard profiles with multi-line AllowedIPs entries were parsed incorrectly.
  • Fixed an issue where re-uploading an OpenVPN profile ZIP file with an additional certificate file would not overwrite the old certificate file upload the first time. (This caused some configurations provided by the VPN service providers to not update properly when manually uploaded again.)
  • Fixed an issue where the router would not recognize USB cellular modems using the M2 EM05G model.
  • Fixed an issue that prevented the VPN from properly following the interface connection status for failover to function when using policy-based proxy mode.
4.5.16 2024-03-30
SHA256: 6254250bbe3c4cf3... 🔗 share
Release notes

V4.5.16

Overview

This release version mainly enhances network security and fixes known issues with network status detection, providing users with the option to manually add languages in the language community and the option to pre-emptively experience the new version. It is compatible with Full Cone NAT and SIP ALG features found in other routers. Optimization, bug fixing, and vulnerability repair for more vendors are shown below.

Supported Models

GL-A1300 Slate Plus, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-MT3000 Beryl AX, GL-MT2500/GL-MT2500A Brume 2, GL-X300B Collie

New features

  • Reconstructed mwan3 and renamed it as kmwan. Optimized failover and load balancing, as well as network status in various scenarios.
  • Added the Security configuration page.
  • Added grayscale testing design. Added RC version subscription and upgrade.
  • Added the communityization of language packs to support manual addition.
  • Added support for IPoE, and support for configuring VLAN ID during DHCP and static dialing.
  • Added Full Cone NAT function.
  • Added the SIP ALG option.
  • Added new temperature protection setting for MTK Wi-Fi.

Improvements

  • Optimized the side route UI interaction and add the option to turn off the DHCP server itself.
  • Optimized the restart process of the relay program.
  • [Only for GL-X300B Collie] Optimized the functionality of RS485, the UI, and localization.
  • Optimized the Tailscale mechanism.
  • Updated language files and pull translation scripts.

Bug fixes

  • Fixed an issue where the interface jumped due to the incorrect change in the client's online time.
  • Fixed an issue with the TTL settings not taking effect.
  • Fixed an issue where scanning always indicated that it was in DFS when all interfaces were disabled.
  • Fixed an issue of failing to enable Wi-Fi for the first time after upgrading.
  • Fixed an issue of failing to connect to the AP due to a failure to parse IE_HT_CAP.
  • Fixed an issue where multiple parsed AllowedIPs were incorrect when parsing the uploaded WireGuard client configuration files.
  • Fixed an IP conflict issue that occured when adding a client profile to WireGuard after modifying the PeerIP of the WireGuard server configuration via SSH.
  • Fixed an issue where inbound data from non-VPN interfaces would not trigger port forwarding rules when VPN was enabled.
  • Fixed an issue where some devices from the TAP-S2S OpenVPN client would not display properly on the client page.
  • Fixed an issue where the OpenVPN server certificate may be lost after rebooting the device.
  • Fixed an issue where selecting manual mode on the MAC address page and entering the factory default MAC address on the ethernet page would result in an unsuccessful configuration even after connecting to the repeater successfully at first.
  • Fixed an issue where the network speed limit feature was still activated after enabling network speed limit, enabling network acceleration, and rebooting the device.
  • Fixed some known vulnerabilities.
4.5.0 2024-01-23
SHA256: f0c5b0343cc561ad... 🔗 share
Release notes

V4.5.0

Overview

This release version mainly enhances network security and fixes known issues with network status detection, providing users with the option to manually add languages in the language community and the option to pre-emptively experience the new version. It is compatible with Full Cone NAT and SIP ALG features found in other routers. Optimization, bug fixing, and vulnerability repair for more vendors are shown below.

This release is available for the following models:
GL-A1300 Slate Plus
GL-AX1800 Flint
GL-AXT1800 Slate AX
GL-MT3000 Beryl AX
GL-MT2500/GL-MT2500A Brume 2
GL-X300B Collie

New features

  • Reconstructed mwan3 and renamed it as kmwan. Optimized failover and load balancing, as well as network status in various scenarios.
  • Added the Security configuration page.
  • Added grayscale testing design. Added RC version subscription and upgrade.
  • Added the communityization of language packs to support manual addition.
  • Added support for IPoE, and support for configuring VLAN ID during DHCP and static dialing.
  • Added Full Cone NAT function.
  • Added the SIP ALG option.
  • Added new temperature protection setting for MTK Wi-Fi.

Improvements

  • Optimized the side route UI interaction and add the option to turn off the DHCP server itself.
  • Optimized the restart process of the relay program.
  • [Only for GL-X300B Collie] Optimized the functionality of RS485, the UI, and localization.
  • Optimized the Tailscale mechanism.
  • Updated language files and pull translation scripts.

Bug fixes

  • Fixed an issue where the interface jumped due to the incorrect change in the client's online time.
  • Fixed an issue with the TTL settings not taking effect.
  • Fixed an issue where scanning always indicated that it was in DFS when all interfaces were disabled.
  • Fixed an issue of failing to enable Wi-Fi for the first time after upgrading.
  • Fixed an issue of failing to connect to the AP due to a failure to parse IE_HT_CAP.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.4.6 2023-10-08
SHA256: 26f67e3f231f9b7c... 🔗 share
Release notes

V4.4.6 - Oct 8,2023

VPN

  • Fixed the problem that the OpenVPN client cannot access the Internet after dialing up, either by rebooting the router or by restarting the feature.

WireGuard

  • Fixed the problem that WireGuard client gets error 'Error: inet6 prefix is expected rather than' when connecting to server.
  • Fixed the problem that the WireGuard client of the device under test does not disconnect after the WireGuard server of the device accompanying the test is shut down, and keeps showing the connection status.

Repeater

  • Fixed the problem that the wireless network connection is abnormal after the router repeater DFS channel.

Tailscale

  • Fixed the problem that when using PPPoE dialup, the Internet cannot be accessed when tailscale is enabled.
  • Fixed the problem that the Good Cloud platform fails to connect when Tailscale is enabled.

Clients

  • Fixed the problem that the black/white list function is not compatible with the old version of blacklist.

Upgrade

  • Fixed the problem that online upgrade reports error '-4,fetch firmware name fail: network unreachable'.

DDNS

  • Fixed the problem that all TCP ports are opened when DDNS is enabled to allow http/https access in reserved configurations.

LAN

  • Fixed the problem that br-lan occasionally hangs when changing LAN IP.

Ethernet

  • Fixed the problem that Wan interface do not work.
4.4.5 2023-08-11
SHA256: e124880e4399dbd7... 🔗 share
Release notes

V4.4.5 - Aug 11,2023

VPN

  • Open VPN server when using tor,delete -4VPN conflict prompt.

GoodCloud

  • Fix MQTT runs abnormally after obtaining 4G/5G information.

Modem

  • Fix M2 demo board cannot recognize SIM card.
  • Fix abnormal display of LTE bandwidth.

Tailscale

  • Add support for accepting routes option.
  • Add support for mutual access between Tailscale subnets.

Dns

  • Fix next-dns setting does not take effect.

WireGuard

  • Fix WireGuard cannot reconnect after working for two days.

Parental Control

  • Fix adding specified url does not take effect.
4.2.3 2023-07-06
SHA256: bc65bcd6c5c4b1c4... 🔗 share
Release notes

Bug Fixes

Fixed the problem that after the MT3000 relays the 160M Hz hotspot, the AP becomes 20M.
Fixed the problem that the AX/AXT1800 cannot access the AP itself after relaying the DFS 140 channel.
Fixed the problem that parental control cannot block blacklist websites in newer browsers.
Fixed the externder working mode, the superior cannot ping the subordinate.
Fixed the problem that openvpn port forwarding fails after the reserved configuration is upgraded.
Fix the problem that mqtt cannot report SSID.
Fixed the problem that ddns occasional interface return error.
Fixed The relay cannot connect to Huawei TC7102 160MHz 5GWiFi.
Fix single sim card slot does not return dual sim card slot information.
Fixed the problem that after the adguardhome function is turned on on the A1300 and the adguardhome is turned off, the visitor has no network.
Fixed the problem that Openvpn Server and wireguard Server shut down remote access to the LAN subnet, but the Openvpn and wireguard clients can still access the IP address of the PC on the LAN side of the server.
Fixed the AP bridge mode, the bridge is not successful. The address assigned by the superior cannot be obtained.
Support-EM160R-EM060K-EM120K-RM520N-modem.
Fixed the problem that A1300 cannot recognize USB3.0 external modem.
Fixed the problem of abnormal equipment caused by the time zone or 160M bandwidth issued by the GoodCloud.
Correct the display problem of the LED light in the unconnected network mode.
Fixed the problem of unsuccessful dialing using external modem, QMI and QCM protocol dialing.
Roll back MTK SDK from v7.6.7.0 to v7.6.6.1.

4.2.1 2023-04-14
SHA256: 977dbc05b88673f7... 🔗 share
Release notes

Bug Fixes

Fixed a problem where the WiFi configuration page showed unavailable channel options.
Fixed a problem where NordVPN could not resolve DNS after keeping settings upgrade.
Fixed a problem where GL-MT3000 failed to recognize USB3.0 modem.
Fixed a problem where the IPV6 rate limiting does not take effect.
Fixed a problem where GL-MT3000 failed to repeat to iPhone 13 and TP-LINK ACR700.
Fixed a memory leak problem in GL-MT3000 when using QCM protocol.
Fixed a probabilistic issue where GL-MT3000 could not apply OpenVPN username and password.
Fixed switch button not taking effect when parental control is enabled on GL-A1300.
Fixed a BUG where clients could not access the internet after failover.

Optimizations

Disabled nginx access logs.
Optimized the MWAN3 online detection threshold.
Optimized the synchronization of configuration files in abnormal situations.
Optimized the repeater scan time of GL-MT3000.

Software Upgrade

Upgraded AdguardHome to V0.107.26.

4.2.0 2023-03-14
SHA256: 3c13b26fbfe9fe17... 🔗 share
Release notes

Language

Added German language.

New feature

Added Parental Control feature.
Added Zerotier feature.
Added Tailscale feature.
Added Clear Traffic Statistics button for in client page.
Added DHCP Gateway option for LAN.
Added SSID Visibility option for guest Wi-Fi.
Added support for GoodCloud alerts when new clients join.
Added support for comments for domain and IP profiles in VPN policy.

Optimization

Improved IPv6 LAN Mode options. Separates the native and passthrough modes.
Improved the results and hints of the DDNS test.
Improved drop-in gateway feature with DHCP-based solution to increase stability.
Improved LED lighting logic to ensure consistency with the UI.
Improved interaction for MAC address cloning.
Improved networking status alerts in Internet page.
Improved interface tracking settings description for Multi-WAN.
Improved login page with automatic focus to password input box.
Improved VPN client configuration file view with files sorted by name.
Improved the switch name in the VPN global options for whether the GL.iNet service uses VPN or not.
Improved the interaction of set read-only users to read-write users in network storage.
Improved ADGuard Home feature to support seeing which client the request is coming from.

4.9.0 beta1 build 1025 2026-05-29
SHA256: b4ceb9935e4230a1... 🔗 share
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
  • Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.

Bug Fixes

  • 2026-05-29: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.9.0 beta1 build 1016 2026-05-21
SHA256: 27f7784c2cbbe31b...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-16: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.8.2 2025-09-12
SHA256: 67e723d0e9bde0d4... 🔗 share
Release notes

V4.8.2

Cautions

The OpenWRT version has been upgraded. Please do NOT keep settings when downgrading to an earlier version. Please backup your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
4.7.13 2025-06-24
SHA256: e2d18ddcf2e845c8... 🔗 share
📝 Extracted from MT2500A factory pre-install (build 2025-06-24). Not published to GL.iNet download API.
Release notes

Changes from 4.7.4 (latest public release)

Factory build 4.7.13 (2025-06-24) vs public release 4.7.4 (2025-03-27).

  • LuCI removed — The full LuCI web interface (25 packages) is no longer pre-installed. GL.iNet replaced it with an “Install Now” button under SYSTEM > Advanced Settings in the main admin panel. Clicking it installs LuCI on demand.
  • ~85 packages updated across the system
  • curl: 7.83.1 → 8.12.1
  • dropbear: 2020.81 → 2024.86
  • Samba: 4.14.12 → 4.18.9
  • 2 new packages: lua-eco-sha256, lua-eco-termios
  • No DISTRIB_REVISION in /etc/openwrt_release (OpenWrt git revision missing)

GL-MT3000 Beryl AX mt3000

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.1 2025-08-19
SHA256: ee038ee0f399c145... SHA256: fc2938dcd26cf8e5... 🔗 share
Release notes

V4.8.1

Overview

This version mainly fixed some known bugs.

Bug Fixes

  • Improved issues related to Direct Routing applications
  • Fixed the issue where DNS requests did not go through the VPN tunnel when AdGuard Home's upstream DNS server was customized to NextDNS's HTTP/3 and QUIC protocols.
  • Fixed the issue where parental controls might not take effect when the VPN client was enabled.
4.8.0 2025-07-23
SHA256: 0c2a582c26ae1d7b... SHA256: 4ced9544682d4421... 🔗 share
Release notes

V4.8.0

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance, allowing support for enabling multiple VPN clients at the same time.
  • Added VPN composite policy, allowing traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only when the VPN policy is based on MAC.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added support for HTTPS in RTTY.
  • Added a one-click option to send logs to technical support.
  • Added support for IPv6 in VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized toggle switch functionality to support Repeater, Wi-Fi and LED light control.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.
4.7.4 2025-03-28
SHA256: 8e27eb7ca690a54b... SHA256: a3aafc265115d05d... 🔗 share
Release notes

V4.7.4

Overview

This version fixes some security vulnerabilities and other bugs.

Bug Fixes

  • Fixed the issue where the failed VPN policy subscription URL request would display an unknown error.
  • Fixed the issue where turning off 'Override DNS Settings of All Clients' would not take effect after enabling AdGuard Home or VPN Client.
  • Fixed the issue where DDNS testing failed to display the WAN address of Ethernet 2.
  • Fixed an issue where no error message was displayed when entering an incorrect old password, while changing the administrator password.
  • Fixed the issue where manually adding a WireGuard Client configuration would incorrectly prompt the error message.
  • Fixed the issue where modifying the administrator password did not log out the current LuCI session.
  • Fixed the issue where the AzireVPN login password containing special characters, such as '$', would incorrectly trigger an 'invalid login info' error message.
  • Fixed the issue where the client name containing a comma prevented address retrieval.
  • Fixed the issue where the GL.iNet APP could not customize client types.
  • Fixed the issue where network storage could not share directories containing special characters.
  • Fixed the issue where Wi-Fi 5G downlink rate decreased after the client was connected for a period of time.
  • Fixed the issue where turning on the 'Camouflage' mode would still fail to pass the portal authentication.
  • Fixed the issue where switching from DHCPv6 to PPPoEv6 prevented the downstream devices from accessing the internet.
  • Fixed the issue where switching to WDS mode, after enabling AP isolation, would cause address acquisition failure.
  • Fixed the issue where the WireGuard Client name field would close automatically when tapping outside the input area.
4.7.0 2024-12-05
SHA256: e32c2e509d737b1b... SHA256: 4410a2524e3dff7b... 🔗 share
Release notes

V4.7.0

Overview

This version introduces several new features and enhancements that improve the interface interaction for overall user experience.

Synchronize Updated Models

Beryl AX (GL-MT3000), Brume 2 (GL-MT2500), Flint 2 (GL-MT6000).

New Features

  • Added device initialization wizard, including settings for administrator and WiFi password, networking connection, VPN and other core functionalities.
  • Added AstroWarp mode (Beta), allowing you to create your own network using aggregated connections and cloud gateways for a high-speed, stable network experience.
  • Added cloud account login functionality, supporting device binding to the cloud from the firmware web page.
  • Added domain name list subscription feature, supporting VPN policies and parental control through URL subscriptions for online domain name or IP list.
  • Added support for Control D DNS.
  • Added AP Isolation function.
  • Added Luci Access Restriction function.
  • Added USB port protocol conversion function, allowing downgrading to use USB 2.0.
  • Added Network Port Management page, supporting scheduled and reboot of automatic updates for Ethernet MAC, WAN/LAN port switching, and displaying network port negotiation rates.
  • Added support for NordVPN, PIA, Surfshark, Hideme, IPVanish WireGuard VPN services, along with AzireVPN registration functionality.

Optimization

  • Optimized the process for manually adding the WireGuard client configuration files and supporting automatic key generation.
  • Optimized the process of configuring vendor profiles for VPN clients.
  • Optimized repeater random MAC settings, supporting scheduled and reboot of automatic updates for repeater MAC.
  • Optimized the detection process for multi-WAN load network status.
  • Optimized OpenVPN Client functionality, allowing modification of configuration file names.
  • Optimized the page names in the web management panel so that the router's hostname is displayed in the browser tab.
  • Optimized the design of interface error messages and interactive elements like input dropdown lists.
  • Upgraded AdGuard Home to version 0.107.52.
  • Upgraded Tor to version 0.4.8.9.
4.6.9 2024-10-30
SHA256: a974ed53c0058cc0... SHA256: 17d8f45a9ae5bf83... 🔗 share
Release notes

V4.6.9

Overview

This release mainly fixes a known bug.

Updated Model

Beryl AX (GL-MT3000)

Bug Fixe

  • Fixed the issue of abnormal transmit power in some cases.
4.6.8 2024-10-14
SHA256: ecb830e1b112b891... SHA256: 5b2946a238032e6b... 🔗 share
Release notes

V4.6.8

Overview

This version mainly focuses on fixing a few known bugs.

Synchronized Updated Models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

Improvement

  • Upgrade AdGuard Home version to v0.107.52.

Bug Fixes

  • Fixed the issue where, after enabling the VPN client and using Global Proxy, enabling AdGuard Home to handle client requests resulted in only localhots 127.0.0.1 appearing in the client list on the settings page.
  • Fixed the issue that TCP port can be probed when WireGuard Server is enabled.
  • Fixed the issue where the 5G wireless disappeared after the device relayed an upstream device with a 5G channel set to 20M dfs.
  • Fixed the issue that resulted in unusual log messages.
  • Fixed the issue where the router's own DNS requests always went through the dnsmasq proxy after switching DNS settings on the page.
4.6.4 2024-09-04
SHA256: e2946cade2d265f3... SHA256: 08d455125d9807db... 🔗 share
Release notes

V4.6.4

Overview

This version mainly focuses on fixing a few known bugs and fixes some security vulnerabilities to enhance the user experience.

Supported Models

GL-AX1800, GL-AXT1800, GL-MT2500/GL-MT2500A, GL-MT3000, GL-MT6000.

Improvement

  • Updated WiFi driver(MT3000).

Bug Fixes

  • Fixed an issue with DNS leaks when upgrading from version 4.5.x reserved configurations to 4.6.x with VPN connected.
  • Fixed the issue that when the 5G main network is not a DFS channel, the 5G main network page will be opened again with a prompt of about 3s for DFS channel availability detection.
  • Fixed a relay scan timeout issue when the WiFi was configured with DFS channels.
  • Fixed the issue where the relay icon did not turn gray when disconnecting the relay connection while the internet connection mode was set to relay and wired.
  • Fixed the issue where language packs were not retained after upgrading with preserved configuration.
  • Fixed the issue where PC WebDAV access would show no data, after enabling WebDAV, inserting a USB drive, and rebooting.
  • Fixed the issue where RTTY-WEB remote access encountered relay scan errors and failed to relay.
  • Fixed a crash of the device's WiFi driver when connecting with a D-Link DWA-192 AC1900 network adapter to 2.4G WiFi.
  • Corrected an issue where adding and applying any custom rule in parental control had no effect on Google Chrome.
  • Fixed an issue where trunks were configured with static IPs, and the trunks showed up as connected even though the trunks were disconnected.
  • Fixed the issue of DNS leakage when VPN Client and DNS encryption are enabled.
  • Corrected a problem where switching internet connection modes did not update the IP address in DDNS resolution.
  • Fixed an issue where videos and images on the USB drive could not be accessed after inserting a USB drive, enabling DLNA, and soft resetting the device.
  • Resolved a DNS leak issue when switching VPN policy from global proxy to IP/domain-based mode.
  • Fixed the issue that the client's hostname was reported to the relay's superior after the relay set a random MAC.
  • Fixed the issue that the WAN port does not show IPv6 address when connecting to a VPN client and then enabling IPv6.
  • Addressed a program crash caused by relay scanning when no other APs were nearby.
  • Corrected a crash caused by wireless scanning of SSIDs containing carriage return characters.
  • Fixed the issue where accessing the device management page using an IPv6 address displayed incorrect MAC cloning information for Ethernet and relay.
  • Fixed the issue where the WebDAV function did not work properly when using an account or password with a length of 64-bit characters.
  • Fixed the issue that after pulling Mullvad VPN configuration, when the corresponding Public Key is deleted from the Mullvad website and the configuration is pulled again, the IP address in the pulled configuration changes to 'The'.
  • Resolved the issue of relay scanning crashing when IBSS exists in the surrounding area.
  • Fixed the issue where firewall rules would occasionally disappear after rebooting the device following a connection to wgclient.
  • Fixed the issue where dip switch is bound to wireguard client, the device turns on ovpn client, and restarting the device causes vpn policy to fail.
  • Fixed the issue where the killswitch failed to work when the DNS service was proxied by the AdGuard program or an encrypted DNS program, and the VPN was in a connected state.
4.6.2 2024-06-28
SHA256: 8b3e636f7e4b5878... SHA256: 577000c83e7e8bd6... 🔗 share
Release notes

V4.6.2

Overview

This version mainly provides the following improvements:

  • Improved the user experience with the repeater feature. Resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Improved the display of IPv6 addresses, and added support for customization of the interface language packs.

Supported models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

New features

  • Added the Login Mode for Public Hotspots and the Camouflage Mode. This resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Added the option to use a randomized BSSID to prevent devices from being traced by BSSID.
  • Added the UI language pack management feature. This allows adding additional language packs and subscribing to language pack updates.
  • Added an option to choose whether the VPN interface uses manually configured DNS. This allows using the VPN's DNS servers, if Encrypted DNS or AdGuard Home is enabled.
  • Added support for port range forwarding and port forwarding rule prioritization options.
  • Added TTL, HL, and MTU options for each interface.
  • Added support for connecting to Wi-Fi via QR code.

Improvements

  • Optimized the repeater feature to enhance performance and user experience. Added support for configuring MAC address for SSIDs individually.
  • Optimized the display of IPv6 address on the Internet page and the Client page.
  • Optimized the MAC address setting logic to support cloning or setting random MAC addresses for each interface.
  • Optimized the status display on the Tethering interface to make a clear distinction between 'disabled' and 'enabled but no device'.
  • Optimized the port forwarding feature. It now has its own page within the admin panel and can function simultaneously as DMZ. The port opening (previously on the Firewall page) has been moved to the Security page.
  • Optimized the logic of jumping after LAN IP is modified so that users do not need to sign in again.
  • Optimized the logic of guest network enabling. If guest Wi-Fi is disabled, guest network will also be disabled.
  • Optimized the logic of toggle switches. When rebooting a device, the enabling status of corresponding services (such as VPN) will be set according to the status of the toggle switch.
  • Removed the length restriction on mobile phone number in SMS sending and forwarding.
  • Removed the option 'Force 20MHz Bandwidth For 2.4G' from the Repeater settings.
  • Upgraded AdGuard Home to version 0.107.46.

Bug fixes

  • Fixed an issue where reserved IP addresses were incorrectly sorted by IP if the IP address range was large.
  • Fixed instances where abnormal issues would occur during firmware grade when “keep settings” was selected during IPv6 mode.
  • Fixed an issue where the reset feature would not work when Tailscale was enabled.
  • Fixed an issue where parental controls would not properly resolve domain names using capital letters (e.g., WWW.GOOGLE.COM).
  • Fixed an issue where manually configured routes would not work in some cases when the VPN client was in custom routing proxy mode.
  • Fixed an issue where the cellular interface would incorrectly determine the internet status of the IPv6 protocol.
  • Fixed an issue where the manual DNS server address in the DNS interface would be invalid after disabling AdGuard Home.
  • Fixed an issue where the imported WireGuard profiles with multi-line AllowedIPs entries were parsed incorrectly.
  • Fixed an issue where re-uploading an OpenVPN profile ZIP file with an additional certificate file would not overwrite the old certificate file upload the first time. (This caused some configurations provided by the VPN service providers to not update properly when manually uploaded again.)
  • Fixed an issue where the router would not recognize USB cellular modems using the M2 EM05G model.
  • Fixed an issue that prevented the VPN from properly following the interface connection status for failover to function when using policy-based proxy mode.
4.5.16 2024-03-30
SHA256: cf2ceedb3f54f296... SHA256: 3dd071864f01dd0f... 🔗 share
Release notes

V4.5.16

Overview

This release version mainly enhances network security and fixes known issues with network status detection, providing users with the option to manually add languages in the language community and the option to pre-emptively experience the new version. It is compatible with Full Cone NAT and SIP ALG features found in other routers. Optimization, bug fixing, and vulnerability repair for more vendors are shown below.

Supported Models

GL-A1300 Slate Plus, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-MT3000 Beryl AX, GL-MT2500/GL-MT2500A Brume 2, GL-X300B Collie

New features

  • Reconstructed mwan3 and renamed it as kmwan. Optimized failover and load balancing, as well as network status in various scenarios.
  • Added the Security configuration page.
  • Added grayscale testing design. Added RC version subscription and upgrade.
  • Added the communityization of language packs to support manual addition.
  • Added support for IPoE, and support for configuring VLAN ID during DHCP and static dialing.
  • Added Full Cone NAT function.
  • Added the SIP ALG option.
  • Added new temperature protection setting for MTK Wi-Fi.

Improvements

  • Optimized the side route UI interaction and add the option to turn off the DHCP server itself.
  • Optimized the restart process of the relay program.
  • [Only for GL-X300B Collie] Optimized the functionality of RS485, the UI, and localization.
  • Optimized the Tailscale mechanism.
  • Updated language files and pull translation scripts.

Bug fixes

  • Fixed an issue where the interface jumped due to the incorrect change in the client's online time.
  • Fixed an issue with the TTL settings not taking effect.
  • Fixed an issue where scanning always indicated that it was in DFS when all interfaces were disabled.
  • Fixed an issue of failing to enable Wi-Fi for the first time after upgrading.
  • Fixed an issue of failing to connect to the AP due to a failure to parse IE_HT_CAP.
  • Fixed an issue where multiple parsed AllowedIPs were incorrect when parsing the uploaded WireGuard client configuration files.
  • Fixed an IP conflict issue that occured when adding a client profile to WireGuard after modifying the PeerIP of the WireGuard server configuration via SSH.
  • Fixed an issue where inbound data from non-VPN interfaces would not trigger port forwarding rules when VPN was enabled.
  • Fixed an issue where some devices from the TAP-S2S OpenVPN client would not display properly on the client page.
  • Fixed an issue where the OpenVPN server certificate may be lost after rebooting the device.
  • Fixed an issue where selecting manual mode on the MAC address page and entering the factory default MAC address on the ethernet page would result in an unsuccessful configuration even after connecting to the repeater successfully at first.
  • Fixed an issue where the network speed limit feature was still activated after enabling network speed limit, enabling network acceleration, and rebooting the device.
  • Fixed some known vulnerabilities.
4.5.0 2024-01-23
SHA256: 233f09c7adaf46a9... SHA256: 2d4ba076a9ba463a... 🔗 share
Release notes

V4.5.0

Overview

This release version mainly enhances network security and fixes known issues with network status detection, providing users with the option to manually add languages in the language community and the option to pre-emptively experience the new version. It is compatible with Full Cone NAT and SIP ALG features found in other routers. Optimization, bug fixing, and vulnerability repair for more vendors are shown below.

This release is available for the following models:
GL-A1300 Slate Plus
GL-AX1800 Flint
GL-AXT1800 Slate AX
GL-MT3000 Beryl AX
GL-MT2500/GL-MT2500A Brume 2
GL-X300B Collie

New features

  • Reconstructed mwan3 and renamed it as kmwan. Optimized failover and load balancing, as well as network status in various scenarios.
  • Added the Security configuration page.
  • Added grayscale testing design. Added RC version subscription and upgrade.
  • Added the communityization of language packs to support manual addition.
  • Added support for IPoE, and support for configuring VLAN ID during DHCP and static dialing.
  • Added Full Cone NAT function.
  • Added the SIP ALG option.
  • Added new temperature protection setting for MTK Wi-Fi.

Improvements

  • Optimized the side route UI interaction and add the option to turn off the DHCP server itself.
  • Optimized the restart process of the relay program.
  • [Only for GL-X300B Collie] Optimized the functionality of RS485, the UI, and localization.
  • Optimized the Tailscale mechanism.
  • Updated language files and pull translation scripts.

Bug fixes

  • Fixed an issue where the interface jumped due to the incorrect change in the client's online time.
  • Fixed an issue with the TTL settings not taking effect.
  • Fixed an issue where scanning always indicated that it was in DFS when all interfaces were disabled.
  • Fixed an issue of failing to enable Wi-Fi for the first time after upgrading.
  • Fixed an issue of failing to connect to the AP due to a failure to parse IE_HT_CAP.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.4.6 2023-10-08
SHA256: 271457630e8d3ef5... SHA256: f8fc92d5cef5225c... 🔗 share
Release notes

V4.4.6 - Oct 8,2023

VPN

  • Fixed the problem that the OpenVPN client cannot access the Internet after dialing up, either by rebooting the router or by restarting the feature.

WireGuard

  • Fixed the problem that WireGuard client gets error 'Error: inet6 prefix is expected rather than' when connecting to server.
  • Fixed the problem that the WireGuard client of the device under test does not disconnect after the WireGuard server of the device accompanying the test is shut down, and keeps showing the connection status.

Repeater

  • Fixed the problem that the wireless network connection is abnormal after the router repeater DFS channel.

Tailscale

  • Fixed the problem that when using PPPoE dialup, the Internet cannot be accessed when tailscale is enabled.
  • Fixed the problem that the Good Cloud platform fails to connect when Tailscale is enabled.

Clients

  • Fixed the problem that the black/white list function is not compatible with the old version of blacklist.

Upgrade

  • Fixed the problem that online upgrade reports error '-4,fetch firmware name fail: network unreachable'.

DDNS

  • Fixed the problem that all TCP ports are opened when DDNS is enabled to allow http/https access in reserved configurations.

LAN

  • Fixed the problem that br-lan occasionally hangs when changing LAN IP.

Ethernet

  • Fixed the problem that Wan interface do not work.
4.4.5 2023-08-11
SHA256: 95d367bf6ade595c... SHA256: c4065f991a74fea9... 🔗 share
Release notes

V4.4.5 - Aug 11,2023

VPN

  • Open VPN server when using tor,delete -4VPN conflict prompt.

GoodCloud

  • Fix MQTT runs abnormally after obtaining 4G/5G information.

Modem

  • Fix M2 demo board cannot recognize SIM card.
  • Fix abnormal display of LTE bandwidth.

Tailscale

  • Add support for accepting routes option.
  • Add support for mutual access between Tailscale subnets.

Dns

  • Fix next-dns setting does not take effect.

WireGuard

  • Fix WireGuard cannot reconnect after working for two days.

Parental Control

  • Fix adding specified url does not take effect.
4.2.3 2023-07-06
SHA256: f5fc45d4196fd088... SHA256: e6c9f3d7b45f3255... 🔗 share
Release notes

Bug Fixes

Fixed the problem that after the MT3000 relays the 160M Hz hotspot, the AP becomes 20M.
Fixed the problem that the AX/AXT1800 cannot access the AP itself after relaying the DFS 140 channel.
Fixed the problem that parental control cannot block blacklist websites in newer browsers.
Fixed the externder working mode, the superior cannot ping the subordinate.
Fixed the problem that openvpn port forwarding fails after the reserved configuration is upgraded.
Fix the problem that mqtt cannot report SSID.
Fixed the problem that ddns occasional interface return error.
Fixed The relay cannot connect to Huawei TC7102 160MHz 5GWiFi.
Fix single sim card slot does not return dual sim card slot information.
Fixed the problem that after the adguardhome function is turned on on the A1300 and the adguardhome is turned off, the visitor has no network.
Fixed the problem that Openvpn Server and wireguard Server shut down remote access to the LAN subnet, but the Openvpn and wireguard clients can still access the IP address of the PC on the LAN side of the server.
Fixed the AP bridge mode, the bridge is not successful. The address assigned by the superior cannot be obtained.
Support-EM160R-EM060K-EM120K-RM520N-modem.
Fixed the problem that A1300 cannot recognize USB3.0 external modem.
Fixed the problem of abnormal equipment caused by the time zone or 160M bandwidth issued by the GoodCloud.
Correct the display problem of the LED light in the unconnected network mode.
Fixed the problem of unsuccessful dialing using external modem, QMI and QCM protocol dialing.
Roll back MTK SDK from v7.6.7.0 to v7.6.6.1.

4.2.2 2023-04-14
SHA256: 4116bdf44ecf6092... SHA256: c19c52712f97dc2d... 🔗 share
Release notes

Bug Fixes

Fixed the problem where the openvpn cannot resolve DNS after restarting openvpn after keeping settings upgrade.
Fixed the problem where the status cannot be displayed correctly when the external modem is connected using the 3G protocol.
Fixed a BUG where clients could not access the internet after failover.
Fixed some UI display exceptions.

Software Upgrade

Upgraded MTK SDK from v7.6.6.1 to v7.6.7.0

4.2.1 2023-03-25
SHA256: 33bd89f20d5f6bdb... SHA256: c70b283cd90355d7... 🔗 share
Release notes

Bug Fixes

Fixed a problem where the WiFi configuration page showed unavailable channel options.
Fixed a problem where NordVPN could not resolve DNS after keeping settings upgrade.
Fixed a problem where GL-MT3000 failed to recognize USB3.0 modem.
Fixed a problem where the IPV6 rate limiting does not take effect.
Fixed a problem where GL-MT3000 failed to repeat to iPhone 13 and TP-LINK ACR700.
Fixed a memory leak problem in GL-MT3000 when using QCM protocol.
Fixed a probabilistic issue where GL-MT3000 could not apply OpenVPN username and password.

Optimizations

Disabled nginx access logs.
Optimized the MWAN3 online detection threshold.
Optimized the synchronization of configuration files in abnormal situations.
Optimized the repeater scan time of GL-MT3000.

Software Upgrade

Upgraded AdguardHome to V0.107.26.

4.2.0 2023-02-23
SHA256: 62e47c1fb29e6ae7... SHA256: 4079ad578f13be56... 🔗 share
Release notes

Language

Added German language.

New feature

Added Parental Control feature.
Added Zerotier feature.
Added Tailscale feature.
Added Clear Traffic Statistics button for in client page.
Added DHCP Gateway option for LAN.
Added SSID Visibility option for guest Wi-Fi.
Added support for GoodCloud alerts when new clients join.
Added support for comments for domain and IP profiles in VPN policy.

Optimization

Improved IPv6 LAN Mode options. Separates the native and passthrough modes.
Improved the results and hints of the DDNS test.
Improved drop-in gateway feature with DHCP-based solution to increase stability.
Improved LED lighting logic to ensure consistency with the UI.
Improved interaction for MAC address cloning.
Improved networking status alerts in Internet page.
Improved interface tracking settings description for Multi-WAN.
Improved login page with automatic focus to password input box.
Improved VPN client configuration file view with files sorted by name.
Improved the switch name in the VPN global options for whether the GL.iNet service uses VPN or not.
Improved the interaction of set read-only users to read-write users in network storage.
Improved ADGuard Home feature to support seeing which client the request is coming from.

4.1.3 2023-01-12
SHA256: 9dada4947fcaf640... SHA256: e02941ab13d00269... 🔗 share
Release notes

Modem

Fix EG25/EC25/EC20 modems qmi dial-up failure

Repeater

Fix the problem of low speed
Fix scan disconnection issue

Wifi

Fix the problem that some channels of wifi in Germany are not displayed

4.9.0 beta4 build 1024 2026-05-29
SHA256: d683f30aad6348f3... SHA256: 848111d8708b6124... 🔗 share
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-29: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.9.0 beta4 build 1023 2026-05-28
SHA256: a4b0bfbb293b7f6e... SHA256: f5801deeb4045df8...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-28: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.9.0 beta4 build 1012 2026-05-25
SHA256: 3d3c56b8df403655... SHA256: 38832a0c12af0b94...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-16: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.9.0 beta3 build 1012 2026-05-13
SHA256: 55c20eaf40bcd2cd... SHA256: 9ccc30d16371c2c4...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.9.0 beta2 build 1006 2026-04-29
SHA256: 2ed92c785b22c64f... SHA256: 55e81f90ab6a778b...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.9.0 beta1 build 1003 2026-04-21
SHA256: 8d121cdcaac8d161... SHA256: 99d458c3f98feace...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • Optimized the configuration retention during upgrades to preserve user-installed plugins.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.8.2 beta6 build 973 2026-03-24
SHA256: 97be7ab6178e0f8d... SHA256: cae52d68dbadc4f4... 🔗 share
📝 Removed from GL.iNet download site on 2026-04-20
Release notes

V4.8.2

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for the AmneziaWG 2.0 obfuscation protocol.
4.8.2 beta5 build 972 2026-03-18
SHA256: e633af2736838bb4... SHA256: b4151f3210e414f0...
Release notes

V4.8.2

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for the AmneziaWG 2.0 obfuscation protocol.
4.8.2 beta4 build 826 2025-09-30
SHA256: 72607b1e3264f39e... SHA256: b591e2c1d77a7ac0...
Release notes

V4.8.2

Overview

This version mainly fixed some known bugs.

New Features

  • Added support for AmneziaWG obfuscation protocol.

GL-MT300N-V2 Mango mt300n-v2

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.25 2025-03-18
SHA256: 05a823f7714848bf... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.18 2024-08-23
SHA256: d2b6c2499c7f7262... 🔗 share
Release notes

V4.3.18

Overview

This version fixes some security vulnerabilities.

Supported models

Slate (GL-AR750S), Creta (GL-AR750), Mudi (GL-E750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300).

4.3.17 2024-06-27
SHA256: 21d51a78ac68bb1b... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300), Convexa-S (GL-S1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.11 2024-03-26
SHA256: 45465178db308156... 🔗 share
Release notes

V4.3.11

Overview

This firmware release provides optimizations, bug fixes, and fixes for security vulnerabilities.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added language support for Korean.
  • (Only available on GL-X750) Added some software packages: kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs.

Bug fixes

  • Fixed an issue with GL-MT300N-V2 where the dip switch and the UI display were reversed.
  • Fixed an issue with GL-MT300N-V2 where wireless terminals could not obtain an address after successfully switching to the Extend and WDS modes.
  • Fixed an issue where two routers acting as the VPN server and the VPN client respectively could not automatically reconnect after disconnection due to network volatility.
  • Fixed an issue where client devices connected through an ethernet cable would not automatically reconnect after the LAN IP address was modified.
  • Fixed a conflicted that occurred with GL-SFT1200 between PPPoE protocol with VLAN ID and hardware acceleration.
  • Fixed an error that happened when a device using PPPoE protocol first switched to the Extender mode and then restored the Route mode.
  • Fixed various known vulnerabilities.
4.3.10 2024-02-06
SHA256: 7ac5bd6b8111a70f... 🔗 share
Release notes

V4.3.10

Overview

This version mainly includes optimizations, bug fixes, and security vulnerability resolutions, as shown below.

This release is available for the following models:
GL-AR300M Shadow
GL-AR300M16 Shadow
GL-AR750 Creta
GL-AR750S-EXT Slate
GL-B1300 Convexa-B
GL-MT300N-V2 Mango
GL-MT1300 Beryl

Bug fixes

  • Fixed deadlock issue in mwan3.

Vulnerability fixes

  • Fixed a vulnerability that allowed arbitrary upload files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed an issue of bypassing Nginx authentication through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users bypassed authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where calling the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, thereby executing arbitrary code. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.3.7 2023-09-13
SHA256: bed878d4bdafef93... 🔗 share
Release notes

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS faeture.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fiwith the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.

BUG fix

  • Fixed the TTL settings not taking effect when fw4 is used.
3.216 2023-03-21
SHA256: 22b0eb598ad18116... 🔗 share
Release notes

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.
4.3.29 beta1 build 463 2026-05-29
SHA256: 6859b545611dcf50... 🔗 share
Release notes

V4.3.29

Overview

This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • 2026-05-28: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.3.29 beta1 build 462 2026-05-25
SHA256: ccf43c138c5175d4...
Release notes

V4.3.29

Overview

This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • 2026-05-20: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.

GL-MT3600BE Beryl 7 mt3600be

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.7 2026-04-17
SHA256: 43aed4181b446a1b... 🔗 share
Release notes

V4.8.7

Overview

  • This version fixes some bugs.
4.8.6 2026-04-09
Firmware (.bin) archived
SHA256: 384954ee11d11eef... 🔗 share
📝 Removed from GL.iNet download site on 2026-04-13
Release notes

V4.8.6

Overview

  • This version fixes some bugs.

Optimization

  • Optimize Wi-Fi connection stability.

New Features

  • Added support for AmneziaWG obfuscation protocol.
4.8.5 2026-01-24
SHA256: 33c5c0cbcb0b8c33... 🔗 share
Release notes

V4.8.5

Overview

  • This release focuses on targeted optimizations of the USB-to-Ethernet data path, improving forwarding performance and link negotiation stability to deliver a better network experience in high-bandwidth scenarios.

Optimization

  • Optimized the USB-to-Ethernet forwarding path, significantly enhancing throughput and overall forwarding stability.

Bug Fixes

  • Fixed an issue where the USB 2.5G Ethernet interface failed to negotiate to 2.5 Gbps in certain scenarios.
  • Fixed an issue where the wired WAN interface exhibited abnormally low upload throughput, restoring normal upstream performance.
4.8.4 2025-12-24
SHA256: 81d4f14cd7b81cda... 🔗 share
Release notes

V4.8.4

Overview

  • release initial version
4.9.0 2026-05-29
SHA256: d44aac3156989617... 🔗 share
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-29: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.8.6 2026-03-17
SHA256: 51cd63bbeb8a8969... 🔗 share
Release notes

V4.8.6

Overview

  • This version fixes some bugs.

Optimization

  • Optimize Wi-Fi connection stability.

New Features

  • Added support for AmneziaWG obfuscation protocol.

GL-MT5000 Brume 3 mt5000

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.6 2026-04-24
SHA256: 001503668d83a939... 🔗 share
Release notes

V4.8.6

Overview

  • This version mainly fixed some known bugs.
4.8.5 2026-04-15
SHA256: 646b3864c213caa1... 🔗 share
Release notes

V4.8.5

Overview

This version mainly fixed some bugs and optimizes the DPI function.

Optimization

  • Optimized the enabling logic of DPI function

Bug Fixes

  • Fixed an issue with SQM rate unit conversion.
  • Fixed an issue where enabling DPI-related features could cause Tailscale's dnsmasq to malfunction.
  • Fixed an issue where the IPV6_NAT network throughput may be abnormally when LAN1 was set to WAN mode.
  • Fixed an issue where abnormal priority of iptables rules caused SYN-ACK packet loss when PPPoE protocol in WAN.
  • Fixed an issue where DDNS failed to report the WAN IP.
  • Fixed an issue where mark on the VPN server caused VPN clients to fail to connect.
4.8.4 2026-01-13
SHA256: 76dcac651bc8aa5d... 🔗 share
Release notes

V4.8.4

Overview

This is the init firmware.

4.9.0 beta1 build 1024 2026-05-29
SHA256: d186718de58b6773... 🔗 share
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
  • Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.

Bug Fixes

  • 2026-05-29: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.9.0 beta1 build 1022 2026-05-28
SHA256: 66bac54031d744f4...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
  • Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.8.5 2026-03-31
Firmware (.bin) archived
SHA256: 0e5598d49eca1fc2... 🔗 share
📝 Removed from GL.iNet download site on 2026-04-17
Release notes

V4.8.5

Overview

This version mainly fixed some bugs and optimizes the DPI function.

Optimization

  • Optimized the enabling logic of DPI function

Bug Fixes

  • Fixed an issue with SQM rate unit conversion.
  • Fixed an issue where enabling DPI-related features could cause Tailscale's dnsmasq to malfunction.
  • Fixed an issue where the IPV6_NAT network throughput may be abnormally when LAN1 was set to WAN mode.
  • Fixed an issue where abnormal priority of iptables rules caused SYN-ACK packet loss when PPPoE protocol in WAN.
  • Fixed an issue where DDNS failed to report the WAN IP.
  • Fixed an issue where mark on the VPN server caused VPN clients to fail to connect.

GL-MT6000 Flint 2 mt6000

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.4 release2 build 879 2026-04-03
SHA256: 45b55eb58d97583c... 🔗 share
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

4.8.4 release1 build 879 2026-03-27
SHA256: e3dee4208d9125b5...
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

4.8.3 2025-10-16
SHA256: 177cb3dbcff52ad7... 🔗 share
Release notes

V4.8.3

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the firmware upgrade function, replacing Release Candidate with Gray Release.

Bug Fixes

  • Fixed an issue where DNS packets failed to be blocked when toggling off the ‘All Other Traffic’ switch during a VPN connection failure, while AdGuard Home was enabled and the tunnel Killswitch was disabled.
  • Fixed an issue in OpenVPN Server mode where the client’s IPv6 DNS was incorrectly pointed to Cloudflare (2606:4700:4700:1001) instead of the server’s tunnel IP after connection.
  • Fixed the issue where the VPN dashboard page renders incompletely and causes content display problems when accessing the Web UI via some older versions of iOS Safari.
4.8.2 2025-09-01
SHA256: c348eadc98a3381f... 🔗 share
Release notes

V4.8.2

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
4.7.7 2025-04-15
SHA256: c04a125b6831a642... 🔗 share
Release notes

V4.7.7

Overview

This version mainly fixed some known bugs.

Bug Fixes

  • Fixed the issue where the transmit power was abnormal in certain situations.
4.7.4 2025-03-28
SHA256: 5c78e3ac46fb32fb... 🔗 share
Release notes

V4.7.4

Overview

This version fixes some security vulnerabilities and other bugs.

Bug Fixes

  • Fixed the issue where the failed VPN policy subscription URL request would display an unknown error.
  • Fixed the issue where turning off 'Override DNS Settings of All Clients' would not take effect after enabling AdGuard Home or VPN Client.
  • Fixed the issue where DDNS testing failed to display the WAN address of Ethernet 2.
  • Fixed an issue where no error message was displayed when entering an incorrect old password, while changing the administrator password.
  • Fixed the issue where manually adding a WireGuard Client configuration would incorrectly prompt the error message.
  • Fixed the issue where modifying the administrator password did not log out the current LuCI session.
  • Fixed the issue where the AzireVPN login password containing special characters, such as '$', would incorrectly trigger an 'invalid login info' error message.
  • Fixed the issue where the client name containing a comma prevented address retrieval.
  • Fixed the issue where the GL.iNet APP could not customize client types.
  • Fixed the issue where network storage could not share directories containing special characters.
  • Fixed the issue where Wi-Fi 5G downlink rate decreased after the client was connected for a period of time.
  • Fixed the issue where turning on the 'Camouflage' mode would still fail to pass the portal authentication.
  • Fixed the issue where switching from DHCPv6 to PPPoEv6 prevented the downstream devices from accessing the internet.
  • Fixed the issue where switching to WDS mode, after enabling AP isolation, would cause address acquisition failure.
  • Fixed the issue where the WireGuard Client name field would close automatically when tapping outside the input area.
4.7.0 2024-12-05
SHA256: eb57b0b596be9446... 🔗 share
Release notes

V4.7.0

Overview

This version introduces several new features and enhancements that improve the interface interaction for overall user experience.

Synchronize Updated Models

Beryl AX (GL-MT3000), Brume 2 (GL-MT2500), Flint 2 (GL-MT6000).

New Features

  • Added device initialization wizard, including settings for administrator and WiFi password, networking connection, VPN and other core functionalities.
  • Added AstroWarp mode (Beta), allowing you to create your own network using aggregated connections and cloud gateways for a high-speed, stable network experience.
  • Added cloud account login functionality, supporting device binding to the cloud from the firmware web page.
  • Added domain name list subscription feature, supporting VPN policies and parental control through URL subscriptions for online domain name or IP list.
  • Added support for Control D DNS.
  • Added AP Isolation function.
  • Added Luci Access Restriction function.
  • Added USB port protocol conversion function, allowing downgrading to use USB 2.0.
  • Added Network Port Management page, supporting scheduled and reboot of automatic updates for Ethernet MAC, WAN/LAN port switching, and displaying network port negotiation rates.
  • Added support for NordVPN, PIA, Surfshark, Hideme, IPVanish WireGuard VPN services, along with AzireVPN registration functionality.

Optimization

  • Optimized the process for manually adding the WireGuard client configuration files and supporting automatic key generation.
  • Optimized the process of configuring vendor profiles for VPN clients.
  • Optimized repeater random MAC settings, supporting scheduled and reboot of automatic updates for repeater MAC.
  • Optimized the detection process for multi-WAN load network status.
  • Optimized OpenVPN Client functionality, allowing modification of configuration file names.
  • Optimized the page names in the web management panel so that the router's hostname is displayed in the browser tab.
  • Optimized the design of interface error messages and interactive elements like input dropdown lists.
  • Upgraded AdGuard Home to version 0.107.52.
  • Upgraded Tor to version 0.4.8.9.
4.6.8 2024-10-17
SHA256: d496846f44cfae16... 🔗 share
Release notes

V4.6.8

Overview

This version mainly focuses on fixing a few known bugs.

Synchronized Updated Models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

Improvement

  • Upgrade AdGuard Home version to v0.107.52.

Bug Fixes

  • Fixed the issue where, after enabling the VPN client and using Global Proxy, enabling AdGuard Home to handle client requests resulted in only localhots 127.0.0.1 appearing in the client list on the settings page.
  • Fixed the issue that TCP port can be probed when WireGuard Server is enabled.
  • Fixed the issue where the 5G wireless disappeared after the device relayed an upstream device with a 5G channel set to 20M dfs.
  • Fixed the issue that resulted in unusual log messages.
  • Fixed the issue where the router's own DNS requests always went through the dnsmasq proxy after switching DNS settings on the page.
4.6.4 2024-09-05
SHA256: f9bf50d5e2b3fbab... 🔗 share
Release notes

V4.6.4

Overview

This version mainly focuses on fixing a few known bugs and fixes some security vulnerabilities to enhance the user experience.

Supported Models

GL-AX1800, GL-AXT1800, GL-MT2500/GL-MT2500A, GL-MT3000, GL-MT6000.

Improvement

  • Updated WiFi driver(MT3000).

Bug Fixes

  • Fixed an issue with DNS leaks when upgrading from version 4.5.x reserved configurations to 4.6.x with VPN connected.
  • Fixed the issue that when the 5G main network is not a DFS channel, the 5G main network page will be opened again with a prompt of about 3s for DFS channel availability detection.
  • Fixed a relay scan timeout issue when the WiFi was configured with DFS channels.
  • Fixed the issue where the relay icon did not turn gray when disconnecting the relay connection while the internet connection mode was set to relay and wired.
  • Fixed the issue where language packs were not retained after upgrading with preserved configuration.
  • Fixed the issue where PC WebDAV access would show no data, after enabling WebDAV, inserting a USB drive, and rebooting.
  • Fixed the issue where RTTY-WEB remote access encountered relay scan errors and failed to relay.
  • Fixed a crash of the device's WiFi driver when connecting with a D-Link DWA-192 AC1900 network adapter to 2.4G WiFi.
  • Corrected an issue where adding and applying any custom rule in parental control had no effect on Google Chrome.
  • Fixed an issue where trunks were configured with static IPs, and the trunks showed up as connected even though the trunks were disconnected.
  • Fixed the issue of DNS leakage when VPN Client and DNS encryption are enabled.
  • Corrected a problem where switching internet connection modes did not update the IP address in DDNS resolution.
  • Fixed an issue where videos and images on the USB drive could not be accessed after inserting a USB drive, enabling DLNA, and soft resetting the device.
  • Resolved a DNS leak issue when switching VPN policy from global proxy to IP/domain-based mode.
  • Fixed the issue that the client's hostname was reported to the relay's superior after the relay set a random MAC.
  • Fixed the issue that the WAN port does not show IPv6 address when connecting to a VPN client and then enabling IPv6.
  • Addressed a program crash caused by relay scanning when no other APs were nearby.
  • Corrected a crash caused by wireless scanning of SSIDs containing carriage return characters.
  • Fixed the issue where accessing the device management page using an IPv6 address displayed incorrect MAC cloning information for Ethernet and relay.
  • Fixed the issue where the WebDAV function did not work properly when using an account or password with a length of 64-bit characters.
  • Fixed the issue that after pulling Mullvad VPN configuration, when the corresponding Public Key is deleted from the Mullvad website and the configuration is pulled again, the IP address in the pulled configuration changes to 'The'.
  • Resolved the issue of relay scanning crashing when IBSS exists in the surrounding area.
  • Fixed the issue where firewall rules would occasionally disappear after rebooting the device following a connection to wgclient.
  • Fixed the issue where dip switch is bound to wireguard client, the device turns on ovpn client, and restarting the device causes vpn policy to fail.
  • Fixed the issue where the killswitch failed to work when the DNS service was proxied by the AdGuard program or an encrypted DNS program, and the VPN was in a connected state.
4.6.2 2024-06-28
SHA256: e2d6f1ce8c24f1d8... 🔗 share
Release notes

V4.6.2

Overview

This version mainly provides the following improvements:

  • Improved the user experience with the repeater feature. Resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Improved the display of IPv6 addresses, and added support for customization of the interface language packs.

Supported models

Flint (GL-AX1800), Slate AX (GL-AXT1800), Beryl AX (GL-MT3000), Brume 2 (GL-MT2500)/(GL-MT2500A), Flint 2 (GL-MT6000).

New features

  • Added the Login Mode for Public Hotspots and the Camouflage Mode. This resolved an issue where most hotspots using Captive Portal could not be repeated.
  • Added the option to use a randomized BSSID to prevent devices from being traced by BSSID.
  • Added the UI language pack management feature. This allows adding additional language packs and subscribing to language pack updates.
  • Added an option to choose whether the VPN interface uses manually configured DNS. This allows using the VPN's DNS servers, if Encrypted DNS or AdGuard Home is enabled.
  • Added support for port range forwarding and port forwarding rule prioritization options.
  • Added TTL, HL, and MTU options for each interface.
  • Added support for connecting to Wi-Fi via QR code.

Improvements

  • Optimized the repeater feature to enhance performance and user experience. Added support for configuring MAC address for SSIDs individually.
  • Optimized the display of IPv6 address on the Internet page and the Client page.
  • Optimized the MAC address setting logic to support cloning or setting random MAC addresses for each interface.
  • Optimized the status display on the Tethering interface to make a clear distinction between 'disabled' and 'enabled but no device'.
  • Optimized the port forwarding feature. It now has its own page within the admin panel and can function simultaneously as DMZ. The port opening (previously on the Firewall page) has been moved to the Security page.
  • Optimized the logic of jumping after LAN IP is modified so that users do not need to sign in again.
  • Optimized the logic of guest network enabling. If guest Wi-Fi is disabled, guest network will also be disabled.
  • Optimized the logic of toggle switches. When rebooting a device, the enabling status of corresponding services (such as VPN) will be set according to the status of the toggle switch.
  • Removed the length restriction on mobile phone number in SMS sending and forwarding.
  • Removed the option 'Force 20MHz Bandwidth For 2.4G' from the Repeater settings.
  • Upgraded AdGuard Home to version 0.107.46.

Bug fixes

  • Fixed an issue where reserved IP addresses were incorrectly sorted by IP if the IP address range was large.
  • Fixed instances where abnormal issues would occur during firmware grade when “keep settings” was selected during IPv6 mode.
  • Fixed an issue where the reset feature would not work when Tailscale was enabled.
  • Fixed an issue where parental controls would not properly resolve domain names using capital letters (e.g., WWW.GOOGLE.COM).
  • Fixed an issue where manually configured routes would not work in some cases when the VPN client was in custom routing proxy mode.
  • Fixed an issue where the cellular interface would incorrectly determine the internet status of the IPv6 protocol.
  • Fixed an issue where the manual DNS server address in the DNS interface would be invalid after disabling AdGuard Home.
  • Fixed an issue where the imported WireGuard profiles with multi-line AllowedIPs entries were parsed incorrectly.
  • Fixed an issue where re-uploading an OpenVPN profile ZIP file with an additional certificate file would not overwrite the old certificate file upload the first time. (This caused some configurations provided by the VPN service providers to not update properly when manually uploaded again.)
  • Fixed an issue where the router would not recognize USB cellular modems using the M2 EM05G model.
  • Fixed an issue that prevented the VPN from properly following the interface connection status for failover to function when using policy-based proxy mode.
4.5.8 2024-04-12
SHA256: 2b23e7309512b161... 🔗 share
Release notes

V4.5.8

Overview

This firmware version brings significant enhancements to Wi-Fi stability and compatibility as well as provides fixes to security vulnerabilities.

Supported Models

GL-MT6000

Improvements

  • Optimized Wi-Fi network speeds and compatibility.
  • Improved stability of Wi-Fi networks.
  • Upgraded Tailscale to version 1.58.2.

Bug Fixes

  • Fixed an issue of slow download speeds with the 2.5Gbps ethernet port.
  • Fixed an issue where Wi-Fi country code and power were shown inaccurately on the LuCI page.
  • Fixed various known vulnerabilities.
4.5.6 2024-01-19
SHA256: 40cb56474375622f... 🔗 share
Release notes

V4.5.6

Bugfixes

  • Fixed wifi driver crash caused by null pointers.
  • Fixed the issue of WiFi 160M speed reduction.
4.5.5 2024-01-05
SHA256: 62939271a2f78191... 🔗 share
Release notes

V4.5.5

Bugfixes

  • Update WiFi firmware.
  • Fixed hardware acceleration enabled, unable to connect to the network after lower level wds.
4.5.4 2023-12-12
SHA256: 0649291142da087c... 🔗 share
Release notes

V4.5.4 - Dec 12 ,2023

Bugfixes

  • Fixed the problem of probability crash when using 2.4G and 5Gwifi at the same time.
  • Fixed abnormal restart of cloud platform service after long-term use.

Vulnerability fix

  • Fixed a vulnerability that allows arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interface in the logread module, which allows arbitrary shell commands to be executed via JSON parameters. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which allowed arbitrary shell commands to be executed through JSON parameters. (CVE-2023-50445)
4.5.3 2023-12-01
SHA256: 44fd56b1fc71d75a... 🔗 share
Release notes

V4.5.3 - Dec 01 ,2023

UI

  • Optimized language packs and prompts.

WiFi

  • Fixed the probabilistic crash problem and restart wifi after relaying.

IPv6

  • Fixed the low wired rate of pppoe in ipv6 native mode.
4.5.2 2023-11-13
SHA256: ee0252409ab844bd... 🔗 share
Release notes

V4.5.2 - Nov 13 ,2023

UI

  • Optimized language packs and prompts.

Tethering

  • Compatible with iOS 16.5.

Upgrade

  • Resolve occasional configuration loss during online upgrades.
  • Network Storage
  • Address WebDAV and Samba exceptions related to anonymous access.
4.5.0 2023-10-17
SHA256: 8e0fe622394a20ee... 🔗 share
Release notes

V4.5.0

Bug fix

  • GL.iNet SDK support MT6000.
4.9.0 beta4 build 1012 2026-05-25
SHA256: c11d4bfa4e7abddb... 🔗 share
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-16: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.9.0 beta3 build 1012 2026-05-13
SHA256: f017d6a7b8c2b183...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.9.0 beta1 build 1003 2026-04-20
SHA256: 0673ed7e38ba6a63...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • Optimized the configuration retention during upgrades to preserve user-installed plugins.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.
4.8.5 2026-03-25
Firmware (.bin) archived
SHA256: 1aefa9ea674aa6fe... 🔗 share
📝 Removed from GL.iNet download site on 2026-04-20
Release notes

V4.8.5

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for the AmneziaWG 2.0 obfuscation protocol.
4.8.4 2026-02-27
Firmware (.bin) archived
SHA256: ae1d562332c78377... 🔗 share
📝 Removed from GL.iNet download site on 2026-03-25
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for AmneziaWG obfuscation protocol.
4.8.99 2026-01-21
Firmware (.bin) archived
SHA256: 62593019784085c2... 🔗 share
📝 Removed from GL.iNet download site on 2026-02-27
Release notes

V4.8.99

New Features

  • Add Data Statistics functionality to monitor router traffic usage.
  • Add Content Protection functionality to block dangerous and malicious websites.
  • Add QoS functionality to optimize bandwidth usage during network congestion.
  • Preinstall SQM functionality to optimize network experience through intelligent queuing.
  • Add VPN Obfuscation functionality to enhance the encrypted transmission security and privacy of VPN networks.

GL-MV1000 Brume mv1000

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
3.218 2024-07-27
SHA256: 252f9e3923778861... 🔗 share
Release notes

V3.218

Overview

This firmware release provides fixes to various bugs and security vulnerabilities.

Supported Models

Velica (GL-B2200), Brume (GL-MV1000), Brume-W (GL-MV1000W), Microuter (GL-USB150), microuter-N300, GL-SF1200.

Bug fixes

  • Fixed an issue that the client device of the router could not get an IP address if the router as a VPN client disconnects and reconnects with an OpenVPN server in S2S-TAP mode.
3.216 2023-03-21
SHA256: 9fa874dc24338798... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

GL-S1300 Convexa-S s1300

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
3.218 2024-07-26
SHA256: e80a8afc4796bcc1... 🔗 share
Release notes

V3.218

Overview

This firmware release provides fixes to various bugs and security vulnerabilities.

Supported Models

Convexa-S (GL-S1300), Cirrus (GL-AP1300).

Bug fixes

  • Fixed an issue that the client device of the router could not get an IP address if the router as a VPN client disconnects and reconnects with an OpenVPN server in S2S-TAP mode.
3.216 2023-04-26
SHA256: 0da982c2cdee7f5c... 🔗 share
Release notes

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)
4.3.13 2024-04-13
SHA256: 0b43aef46893bdee... SHA256: 92918247037732a7... 🔗 share
Release notes

V4.3.13

Overview

This version mainly includes optimizations, bug fixes, and security vulnerability resolutions, as shown below.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S-EXT,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added support for Korean.
  • Added some software packages (kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs) to GL-X750.

Bug fixes

  • Fixed the issue that routers acting as VPN server and client could not automatically reconnect after disconnecting due to network volatility.
  • Fixed the issue that client devices connected through a Ethernet cable would not automatically reconnect after modifying the LAN IP address.
  • Fixed the issue that an error would be prompted when a device using PPPoE protocol first switches to Extender mode and then restores Route mode.
  • Fixed the issue with GL-X750 that the returned SIM card slot information is abnormal if the SIM card is not registered.
  • Removed the USSD code limit to GL-X750.
  • Fixed the issue of not being able to find the host when the WG blocking non-VPN traffic option and the option based on destination domain or IP are enabled.
  • Fixed some known vulnerabilities.

GL-SF1200 sf1200

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
3.218 2024-07-09
SHA256: 9c278d2b45d2071a... 🔗 share
Release notes

V3.218

Overview

This firmware release provides fixes to various bugs and security vulnerabilities.

Supported Models

Velica (GL-B2200), Brume (GL-MV1000), Brume-W (GL-MV1000W), Microuter (GL-USB150), microuter-N300, GL-SF1200.

Bug fixes

  • Fixed an issue that the client device of the router could not get an IP address if the router as a VPN client disconnects and reconnects with an OpenVPN server in S2S-TAP mode.
3.216 2023-03-21
SHA256: a7cadbdd0e735a11... 🔗 share
Release notes

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

GL-SFT1200 Opal sft1200

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.25 2025-03-07
SHA256: 294611525e549867... SHA256: 095e16f4d4c30e62... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.24 2025-01-15
SHA256: 38ba1d9cab5ff812... SHA256: 18553e0de02a3083... 🔗 share
Release notes

V4.3.24

Overview

This version mainly fixes some known bugs.

Synchronized Updated Model

Opal(GL-SFT1200).

Bug Fixes

  • Fixed the issue of abnormal transmit power in some cases.
  • Fixed the problem of abnormal display of channel list in some cases.
4.3.21 2024-10-16
SHA256: e4eabfb15eb958aa... SHA256: 1655adc90864572d... 🔗 share
Release notes

V4.3.21

Overview

This version mainly fixes bugs and security vulnerabilities.

Supported Models

Opal(GL-SFT1200).

Bug Fixes

  • Fixed an issue where the device would not be forcibly disconnected from the logged-in RTTY-SSH and RTTY-web after being bound to the cloud platform.
  • Fixed an issue where the closed port rule would not disconnect the connected remote ssh.
  • Fixed an issue where the name of the configuration file uploaded by the OpenVPN and WireGuard VPN client contains ~, causing file uploading failure.
  • Fixed an issue where the Client list displayed the device offline for a long time.
  • Fixed an issue where unauthenticated devices could set DFS channels through LuCI.
  • Fixed an issue where dialing from an external modem fails when QMI is selected as the protocol, the APN is set manually, and PAP/CHAP is chosen as the authentication method.
  • Fixed an issue where the SMS page could not be opened when the USB port was connected to the external M2 (RM520N) module.
  • Fixed an issue that the web home page displays abnormally when the WAN port static address, eth0.2 interface address is not cleared after unplugging the WAN port cable.
  • Fixed an issue where the lua-cjson package update failed.
4.3.19 2024-08-23
SHA256: 558401f701b2a820... SHA256: 5d76f8470a7b3b3b... 🔗 share
Release notes

V4.3.19

Overview

This version fixes some security vulnerabilities.

Supported models

Beryl (GL-MT1300), Spitz (GL-X750), Opal (GL-SFT1200).

4.3.18 2024-07-26
SHA256: f7ddbddf679c808b... SHA256: dbbfaf51b241e495... 🔗 share
Release notes

V4.3.18

Overview

This version introduces new SIM APN support, alongside various bug fixes and security enhancements.

Supported Models

Beryl(GL-MT1300), Spitz(GL-X750V2), Opal(GL-SFT1200).

New Features

  • Added APN support for Webbing SIM cards (WeData)(GL-X750V2).

Bug Fixes

  • Fixed the issue where the device fails to connect to the network via QMI or QCM protocols when a telecom card is inserted and IPv6 is enabled.
  • Fixed the issue of dnscrypt generating unnecessary logs on SFT1200 devices.
  • Fixed the misidentification of LAN port speed on SFT1200 devices.
  • Fixed the issue where the default LUCI page of SFT1200 only supports English configurations, excluding Chinese.
  • Fixed the generation of unnecessary netclash logs during the startup process.
  • Fixed dial-up failures on the modem during the dialing process when using QMI protocol, manually setting APN, and selecting PAP/CHAP authentication.
4.3.17 2024-06-07
SHA256: 99b662d97d5f6bf5... SHA256: 4ccd22643136a91c... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.11 2024-03-21
SHA256: 92149b8d7d17fd50... SHA256: 9e12cbb46699d987... 🔗 share
Release notes

V4.3.11

Overview

This firmware release provides optimizations, bug fixes, and fixes for security vulnerabilities.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added language support for Korean.
  • (Only available on GL-X750) Added some software packages: kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs.

Bug fixes

  • Fixed an issue with GL-MT300N-V2 where the dip switch and the UI display were reversed.
  • Fixed an issue with GL-MT300N-V2 where wireless terminals could not obtain an address after successfully switching to the Extend and WDS modes.
  • Fixed an issue where two routers acting as the VPN server and the VPN client respectively could not automatically reconnect after disconnection due to network volatility.
  • Fixed an issue where client devices connected through an ethernet cable would not automatically reconnect after the LAN IP address was modified.
  • Fixed a conflicted that occurred with GL-SFT1200 between PPPoE protocol with VLAN ID and hardware acceleration.
  • Fixed an error that happened when a device using PPPoE protocol first switched to the Extender mode and then restored the Route mode.
  • Fixed various known vulnerabilities.
4.3.7 2023-12-22
SHA256: 8eec38e33fe348b8... SHA256: cd208e7b7e7f4c71... 🔗 share
Release notes

V4.3.7

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version of firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version of firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750,MV1000).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS feature.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fi with the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.
  • Optimized VPN configuration file generation and parsing speed.

Bug fix

  • Fixed the TTL settings not taking effect when fw4 is used.
  • Fixed VPN DNS leak.

Vulnerability fix

  • Fixed a vulnerability that allowed arbitrary files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed a bypassing vulnerability where Nginx authentication could be bypassed through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users could bypass authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where accessing the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, executing arbitrary code in the process. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interfaces of the logread module, which could allow arbitrary shell commands to be executed via JSON parameters, posing a significant security threat. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which could allow arbitrary shell commands to be executed through JSON parameters, representing a significant security risk. (CVE-2023-50445)
3.216 2023-03-21
SHA256: 5a88a3f715a3457c... SHA256: 928bf870e4629dd8... 🔗 share
Release notes

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)
4.8.3 beta7 build 1005 2026-05-28
SHA256: ac877937f20d704e... SHA256: 10223513a9da5df7... 🔗 share
Release notes

V4.8.3

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy, allowing traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only when the VPN policy is based on MAC.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added support for HTTPS in RTTY.
  • Added a one-click option to send logs to technical support.
  • Added support for IPv6 in VPN.
  • Added network storage functionality.

Optimization

  • Refactored the Cellular function to improve performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized toggle switch functionality to support Repeater, Cellular, Wi-Fi and LED light control.
  • Optimized VPN setup wizard to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Upgrade function, replacing Release Candidate with Gray Release.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.1.
  • Upgraded Stubby to version 0.4.3.
  • Optimized the Repeater's detection logic of Captive Portal to be compatible with identifying more authentication pages in different formats.
  • Optimized the switching logic of the Repeater; when the internet is already connected, the repeater will not scan for available networks to ensure wireless communication quality.

Removal

  • Removed Tor function due to insufficient remaining memory.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
  • Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.8.3 beta6 build 1003 2026-05-15
SHA256: aae29538728b8d1d... SHA256: 6b881cb8a52eac1a...
Release notes

V4.8.3

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy, allowing traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only when the VPN policy is based on MAC.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added support for HTTPS in RTTY.
  • Added a one-click option to send logs to technical support.
  • Added support for IPv6 in VPN.
  • Added network storage functionality.

Optimization

  • Refactored the Cellular function to improve performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized toggle switch functionality to support Repeater, Cellular, Wi-Fi and LED light control.
  • Optimized VPN setup wizard to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Upgrade function, replacing Release Candidate with Gray Release.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.1.
  • Upgraded Stubby to version 0.4.3.
  • Optimized the Repeater's detection logic of Captive Portal to be compatible with identifying more authentication pages in different formats.
  • Optimized the switching logic of the Repeater; when the internet is already connected, the repeater will not scan for available networks to ensure wireless communication quality.

Removal

  • Removed Tor function due to insufficient remaining memory.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
4.8.3 beta5 build 1001 2026-04-22
SHA256: 5f12e2a4426f686a... SHA256: 77f4e90204a5dc1f...
Release notes

V4.8.3

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy, allowing traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only when the VPN policy is based on MAC.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added support for HTTPS in RTTY.
  • Added a one-click option to send logs to technical support.
  • Added support for IPv6 in VPN.
  • Added network storage functionality.

Optimization

  • Refactored the Cellular function to improve performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized toggle switch functionality to support Repeater, Cellular, Wi-Fi and LED light control.
  • Optimized VPN setup wizard to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Upgrade function, replacing Release Candidate with Gray Release.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.1.
  • Upgraded Stubby to version 0.4.3.
  • Optimized the Repeater's detection logic of Captive Portal to be compatible with identifying more authentication pages in different formats.
  • Optimized the switching logic of the Repeater; when the internet is already connected, the repeater will not scan for available networks to ensure wireless communication quality.

Removal

  • Removed Tor function due to insufficient remaining memory.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
4.8.3 beta3 build 947
SHA256: 94733b736080e1e3... SHA256: d7b8035e30f45a37... SHA256: 18348da7638ebe28... SHA256: 5ef12a9946b1454e...
Release notes

V4.8.3

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy, allowing traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only when the VPN policy is based on MAC.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added support for HTTPS in RTTY.
  • Added a one-click option to send logs to technical support.
  • Added support for IPv6 in VPN.
  • Added network storage functionality.

Optimization

  • Refactored the Cellular function to improve performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized toggle switch functionality to support Repeater, Cellular, Wi-Fi and LED light control.
  • Optimized VPN setup wizard to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Upgrade function, replacing Release Candidate with Gray Release.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.1.
  • Upgraded Stubby to version 0.4.3.
  • Optimized the Repeater's detection logic of Captive Portal to be compatible with identifying more authentication pages in different formats.
  • Optimized the switching logic of the Repeater; when the internet is already connected, the repeater will not scan for available networks to ensure wireless communication quality.

Removal

  • Removed Tor function due to insufficient remaining memory.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
  • Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.7.2 2025-04-21
SHA256: d8bf5a84ae24d285... SHA256: f003f995dc99f45e... 🔗 share
Release notes

V4.7.2

Overview

This version introduces several new features and enhancements that improve the interface interaction for overall user experience.

New Features

  • Added device initialization wizard, including administrator and WiFi password, networking, VPN and other core function settings.
  • Added AstroWarp mode (Beta), with AstroWarp, you can create your own network using aggregated connections and cloud gateways for a high-speed and stable network experience.
  • Added the Cloud account login function, supporting device binding to the cloud from the firmware web page.
  • Added Domain Name List Subscription function, support VPN policy and parental control to subscribe to online domain name or IP list via URL.
  • Added the AP Isolation function.
  • Added the Luci Access Restriction function.
  • Added the Network Port Management page, supporting scheduled and restart of automatic Ethernet MAC updates, WAN/LAN port switching, and displaying network port negotiation rates.
  • Added NordVPN, PIA, Surfshark, Hideme, IPVanish WireGuard VPN, and support AzireVPN registration function.

Optimization

  • Optimized the process for manually adding the WireGuard client configuration file and supporting automatic key generation.
  • Optimized the process for configuring vendor profiles for VPN clients.
  • Optimized Repeater random MAC setting, supporting scheduled and restart of automatic Repeater MAC updates.
  • Optimized the flow of Multi-WAN load network status detection.
  • Optimized OpenVPN Client functionality to allow modification of configuration file names.
  • Optimized page names in the web Administration Panel so that the router is host name appears in the browser tab.
  • Optimized page interactions such as interface error messages and inputable drop-down list designs.

GL-USB150 Microuter usb150

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
3.218 2024-07-09
SHA256: c4f3f7b857589e0b... 🔗 share
Release notes

V3.218

Overview

This firmware release provides fixes to various bugs and security vulnerabilities.

Supported Models

Velica (GL-B2200), Brume (GL-MV1000), Brume-W (GL-MV1000W), Microuter (GL-USB150), microuter-N300, GL-SF1200.

Bug fixes

  • Fixed an issue that the client device of the router could not get an IP address if the router as a VPN client disconnects and reconnects with an OpenVPN server in S2S-TAP mode.
3.216 2023-03-21
SHA256: 75ea7363b5ae0d53... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

GL-X2000 Spitz Plus x2000

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.7.13 2025-06-20
SHA256: 83844f777d2cdf61... 🔗 share
Release notes

V4.7.13

Overview

This version includes adjustments to enhance device security.

New Features

  • Added Setup guide function.
  • Added eSIM function.
  • Added Lock Tower function.
  • Added serial port encryption.
  • Added Tailscale function.
  • Added Control D DNS function.
  • Added Module Online Upgrade and Module Local Upgrade functions.
  • Added a global SSH toggle; the SSH switch can only be enabled if the administrator password is set to a strong password.
  • Added modem ip type configuration option.

Optimization

  • Added a user privacy policy statement to the initialization wizard page.
  • Added a security warning when WiFi security is set to OPEN.
  • SSH and serial input are automatically disabled if the administrator password is set to a weak password.
  • Added anti-brute-force mechanisms for Samba services, enforcing the use of strong passwords.
  • WebDAV protocol uses HTTPS by default, and a security warning is displayed when HTTP is used.
  • Optimized the network abnormal traffic protection mechanism, adding flood protection for ICMP and other protocols.
  • LuCI functionality is no longer pre-installed; users can install LuCI with one click on the advanced settings page.
  • Optimized Nginx log management, adding login and configuration change logs. Logs are automatically synchronized to Flash upon reboot.

Bug Fixes

  • Fixed the problem that Mac addresses were not restored when MAC cloning was performed after LAN switching to WAN and then restoring to LAN.
  • Fixed the issue that the relay client in the list kept jumping between online and offline when the whitelist function was enabled on the device client.
  • Fixed the problem that Modem cannot dial successfully when setting dialing manually and APN selection is empty.
  • Fixed the problem that when WG Client configuration is modified and the configuration name is entered as a space only, the web page reports an error after application.
  • Fixed the problem that the SIM card would not switch automatically when the SIM card is abnormal after the SIM card automatic switching function is turned on.
  • Fixed an issue in which after adjusting the modem failover priority and rebooting the system, the priority would revert to its default value.
  • Fixed the problem that simultaneously modifying the LAN IP and subnet mask resulted in the client is inability to obtain an IP address.
  • Fixed the issue where the device had a battery module on the cloud platform base page, but kept spinning around.
  • Fixed an issue where the parental control schedule rules displayed incorrectly when switching time zones again due to the time zone discrepancy between the router and the browser.
4.5.26 2025-03-04
SHA256: 80e63f2eb3c8a771... 🔗 share
Release notes

V4.5.26

Overview

This version mainly fixes some known defects.

Bug Fixes

  • Fixed an issue where apn could not be configured via the failover page after enabling failover and rebooting the device.
4.5.25 2025-02-26
SHA256: dbd2b0c2fdd2ed3b... 🔗 share
Release notes

V4.5.25

Overview

This version mainly fixes some known defects.

Improvement

  • Removed invalid QMI protocol selection.

Bug Fixes

  • Fixed an issue where IPQ5018 and EG120K could not communicate due to probabilistic channel blocking.
  • Fixed the issue of missing file configuration for traffic statistics leading to incorrect traffic data.
  • Fixed an issue where the switch card does not dial after the traffic exceeds the limit.
  • Fixed the problem that the auto dialer cannot set the APN.
4.5.23 2024-12-19
SHA256: 224b39b1b5a0e5f1... 🔗 share
Release notes

V4.5.23

Overview

This is initial firmware.

Improvement

  • Fix memory leaks caused by lua eco and single_open.
4.5.20 2024-11-22
SHA256: 582549fbe0b5252d... 🔗 share
Release notes

V4.5.20

Overview

This version mainly focuses on fixing a few known bugs.

Synchronized Updated Model

GL-X2000.

Improvement

  • Optimize web interface.
  • Optimize cellular-related features.

Bug Fixes

  • Fixed an issue where enabling AdGuard Home would reset custom DNS encryption settings during configuration upgrades.
  • Fixed an IPv6 connectivity issue where PCs on the LAN side could not ping devices when in IPv6 Passthrough mode.
  • Fixed an issue where wireless switching would cause the repeater to disconnect when the repeater was enabled.
  • Fixed an issue where the network still displayed the previous name after modifying the Samba service name.
4.5.13 2024-10-12
SHA256: 425ade50a81937b2... 🔗 share
Release notes

V4.5.13

Overview

This is initial firmware.

Supported Models

GL-X2000

4.8.2 2025-09-29
SHA256: eda8aee835f5506f... 🔗 share
Release notes

V4.8.2

Cautions

The OpenWRT version has been upgraded. Please do NOT keep settings when downgrading to an earlier version. Please backup your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized toggle switch functionality to support Repeater, Wi-Fi and LED light control.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the device binding functionality of the GoodCloud platform.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018

GL-X3000 Spitz AX x3000

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.3 2025-11-13
SHA256: 877500360e81c65c... 🔗 share
Release notes

V4.8.3

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized vSIM functionality.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12, support dco to improve OpenVPN performance.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
4.7.4 2025-03-17
SHA256: 1b8ba38275c7f23f... 🔗 share
Release notes

V4.7.4

Overview

This version introduces several new features and enhancements that improve the interface interaction for overall user experience.

Synchronize Updated Models

Puli AX(GL-XE3000), Spitz AX(GL-X3000).

New Features

  • Added device initialization wizard, including settings for administrator and WiFi password, networking connection, VPN and other core functionalities.
  • Added AstroWarp mode (Beta), allowing you to create your own network using aggregated connections and cloud gateways for a high-speed, stable network experience.
  • Added cloud account login functionality, supporting device binding to the cloud from the firmware web page.
  • Added domain name list subscription feature, supporting VPN policies and parental control through URL subscriptions for online domain name or IP list.
  • Added support for Control D DNS.
  • Added AP Isolation function.
  • Added Luci Access Restriction function.
  • Added Network Port Management page, supporting scheduled and reboot of automatic updates for Ethernet MAC, WAN/LAN port switching, and displaying network port negotiation rates.
  • Added support for NordVPN, PIA, Surfshark, Hideme, IPVanish WireGuard VPN services, along with AzireVPN registration functionality.
  • Added cellular data traffic statistics feature.

Optimization

  • Optimized the process for manually adding the WireGuard client configuration files and supporting automatic key generation.
  • Optimized the process of configuring vendor profiles for VPN clients.
  • Optimized repeater random MAC settings, supporting scheduled and reboot of automatic updates for repeater MAC.
  • Optimized the detection process for multi-WAN load network status.
  • Optimized OpenVPN Client functionality, allowing modification of configuration file names.
  • Optimized the page names in the web management panel so that the router's hostname is displayed in the browser tab.
  • Optimized the design of interface error messages and interactive elements like input dropdown lists.
  • Upgraded AdGuard Home to version 0.107.52.
  • Upgraded Tor to version 0.4.8.9.
  • Optimized the display of MCC/MNC data in Cellular settings, after scanning the BTS and Cell information pages, providing readable carrier operator names on the respective information pages.
  • Optimized NSA signal selection in Cellular settings, ensuring 5G NSA band and LTE band work together. This means that configuring 5G NSA requires you to also configure the LTE band.
  • Optimized the firmware upgrade process (manual, online, and via the cloud platform) by adding memory detection alerts to prompt users to clear memory when the device storage is insufficient.
  • Optimized eSIM functionality.
  • Optimized the reporting of cellular traffic data to the cloud platform and the SIM lock alert system.

Bug Fixes

  • Fixed an issue where the name of a wired connection in the client list was displayed as 'unknown' when the client connected to the device using both wired and wireless methods simultaneously.
  • Resolved an issue where certain mobile phones (e.g., Xiaomi 10, Huawei) could not connect via QR code when the 2.4G Guest Wi-Fi was encrypted with WPA3 or hidden.
  • Fixed an issue where port forwarding rules remained active even when the DMZ priority was set to the highest level.
  • Addressed a bug where devices in a Tailnet organization with a Tailscale email domain name randomly displayed the email addresses of other devices in the same organization.
  • Fixed an issue where the first modification of MAC mode did not take effect after a successful relay connection.
  • Resolved a problem where manually configured APN settings reverted to default after a router restart.
  • Fixed a DNS leakage issue that occurred when connecting to a VPN client via a wired network with IPv6 and Modem dialing enabled.
  • Corrected a problem where changing the password of one wireless band disconnected clients on other bands.
  • Fixed an issue where the randomized BSSID was automatically disabled after Wi-Fi configurations were modified via the cloud platform.
  • Resolved an issue where the page displayed 'Checking for channel availability' even when the selected 5G Wi-Fi channel was not a DFS channel.
  • Addressed a problem where the WAN port provided DHCP services in Drop-in Gateway mode when the 'Some devices select their own networking gateway' option was enabled.
  • Fixed an issue where IPv6 online status detection was not performed on external M.2 modules.
  • Corrected an error where the page reported an 'unknown error' when a PPPoE username or password exceeded 256 characters.
  • Fixed a bug where established SSH connections remained active even after Remote SSH was turned off.
4.4.13 2024-10-25
SHA256: ad2279cca36b9730... 🔗 share
Release notes

V4.4.13

Overview

This release mainly added eSIM and Cellular module update functions, and fixed some known bugs.

Synchronized Updated Models

Puli AX (GL-XE3000), Spitz AX (GL-X3000)

New Features

Added eSIM functionality. Added Cellular module update feature.

Bug Fixes

  • Fixed the issue where enabling parental controls and adding a schedule to disable Internet access in repeater networking prevented devices in the disabled Internet group from accessing web pages.
  • Fixed the issue where dailing with a modem failed when the protocol was set to QMI, the APN was manually configured, and the authentication method was set to PAP/CHAP.
  • Fixed the issue where the repeater could not scan for the 5GHz upstream wireless network when it was set to 20M on channel 165.
4.4.12 2024-09-20
SHA256: 1a8981598fc49150... 🔗 share
Release notes

V4.4.12

Overview

This release mainly fixes some known issues, optimizes features and adds new feature.

Support Models

Puli AX (GL-XE3000), Spitz AX (GL-X3000)

Function Added

Added the cellular module update function.

Improvement

  • Updated Wi-Fi driver.
  • Upgrade AdGuard Home version to v0.107.46.

Bug Fixes

  • Fixed the issue that the rtty connection of cloud platform will not be disconnected after the login password is changed.
  • Fixed the issue that dialling fails due to PIN unlock failure when using multiple APNs.
  • Fixed the issue that SSH connection will not be disconnected when ports 80 and 22 are closed.
  • Fixed the issue where relay scanning for SSIDs with carriage return characters caused the relay program to crash.
  • Fixed a DNS leak issue with VPN.
  • Fixed an issue with AdGuard Home configuration errors.
  • Fixed the issue that wgclient connects to wgserver on local LAN and occasionally loses firewall rules after rebooting the device.
  • Fixed the issue that WebDAV data cannot be accessed after rebooting the device.
4.4.11 2024-08-24
SHA256: 00b1ee7136ba0654... 🔗 share
Release notes

V4.4.11

Overview

This version fixes some security vulnerabilities.

Supported Models

Puli AX (GL-XE3000), Spitz AX (GL-X3000).

4.4.9 2024-06-15
SHA256: 7ef4c2fd55f108b3... 🔗 share
Release notes

V4.4.9

Overview

This version add support for Webbing SIM cards and fixes some security vulnerabilities and other bugs.

Supported models

Puli AX (GL-XE3000), Spitz AX (GL-X3000).

New features

  • Added support for Webbing SIM card, the device will now automatically set the APN to wedata for it.
  • Added the cellular auto-dialing feature when the Webbing SIM card is detected at boot-up.

Bug fixes

  • Fixed an issue that cellular network cell information was displayed incorrectly.
  • Fixed the issue that after manually disabling Tailscale and powering off the device, Tailscale will be enabled automatically when the device is rebooted.
  • Fixed the issue that after manually disabling DDNS and powering off the device, DDNS will be enabled automatically when the device is rebooted.
  • Fixed an issue where a warning was not displayed on the cellular icon on the Internet page when the cellular network could not connect to the Internet.
  • Fixed an issue that devices could not reset correctly when Tailscale was enabled.
  • Fixed an issue where uploading an OpenVPN/WireGuard client's profile name containing the character ~ would cause the upload to fail.
  • Fixed an issue that cellular network traffic statistics are displayed incorrectly.
  • Fixed an issue that WireGuard server would show the displayed offline clients as online.
  • Fixed some interface text errors.
4.4.8 2024-04-19
SHA256: 9e6bba950d8bd744... 🔗 share
Release notes

V4.4.8

Overview

This firmware version mainly provides fixes to bugs and security vulnerabilities.

Supported Models

GL-X3000

Improvements

  • Upgraded Tailscale to version 1.58.2.

Bug Fixes

  • Fixed an internet disconnection issue caused by network detection of the cellular interface.
  • Fixed an abnormal IPv6 network issue when IPv6 NAT6 used the ddxx:: prefix.
  • Fixed the issue that PIN code does not work.
  • Fixed an issue where ICCID hexadecimal was displayed incorrectly.
  • Fixed a rare issue where the route rmnet_mhi0 would not update.
  • Fixed an issue where DNS resolution would not work if the Block Non-VPN Traffic option was enabled when using proxy mode based on destination domain name or IP.
  • Fixed an issue where repeater would fail if all Wi-Fi networks were disabled.
  • Fixed an issue where cloud disconnection after turning on AdguardHome or configuring DNS.
  • Fixed some known vulnerabilities.
4.4.6 2024-01-23
SHA256: 904554f4bf3641c5... 🔗 share
Release notes

V4.4.6

BUG fix

  • Optimize passthrough.
  • Fixed conflicting mnc/mcc.
  • Fixed the DNS display error on DNS function page after enabling VPN.
4.4.5 2024-01-03
SHA256: d977500dc0f1811a... 🔗 share
Release notes

BUG fix

  • Update APN support list [American.bics, bicsapn].
  • Add cellular offline document prompt.
4.4.4 2023-12-14
SHA256: 49479ddaf54518fd... 🔗 share
Release notes

BUG fix

  • Add an explanation for the 4G+ display.
  • Fixed some shell injection vulnerabilities.
  • Fixed APN errors.
  • Fixed the issue of switching to SIM card 2 after keeping configuration upgrade.
  • Optimize prompts:'The interface is connected,but the internet can't be accessed.
  • When switching SIM cards, shield buttons such as 'Automatic connection, Manual...' to prevent cellular related operations.
  • Optimize failover function for mwan3.
4.4.3 2023-11-15
SHA256: c1a156982997b4d2... 🔗 share
Release notes

BUG fix

  • Fixed modem status monitor.
  • Fixed the issue of retaining configuration changes to the IP address during module upgrades without requiring a full update.
  • Optimize the cellular dialing function.
  • Add an explanation for the 4G+ display.
  • Modify the repeater display to show 'Repeater (Wi-Fi as WAN)'.
  • Fixed cloud memory leaks.
4.4.2 2023-09-08
SHA256: 1e4ab22816a36a4d... 🔗 share
Release notes

BUG fix

  • Add the ability to lock onto a specific cell tower.
  • Add real-time display of signal commands.
  • Add the Orange configuration module.
  • Fixed the error in displaying LTE bandwidth.
  • Fixed the issue where the VERIZON APN module configuration fails to take effect.
  • Optimize the tower configuration.
  • Resolve the signal strength display error.
  • Introduce the signal upload function to the cloud platform.
  • Ensure compatibility with time-consuming AT commands.
  • Fixed Tmobile restart dial exception.
4.3.5 2023-07-07
SHA256: 143b15b0da853b36... 🔗 share
Release notes

BUG fix

Add configuration for cellular IPV6 TTL.
Improve logic configuration for SIM cards.
Fixed address allocation issue in extender mode.

4.3.4 2023-06-25
SHA256: 487e4b266ef39f33... 🔗 share
Release notes

BUG fix

Add IPV6 passthrough features.
Add display for 5G NSA, 5G SA, and 4G+.
Fix the issue of incorrect signal strength in NSA mode.
Fix the issue where the module incorrectly displays dl_bandwidth and ul_bandwidth.
Optimized Cellular settings interface interaction.

4.3.3 2023-06-14
SHA256: a80d9cd7150e29bb... 🔗 share
Release notes

BUG fix

Fix TMO failover.
Fix SIM configuration loss.
Add the display of web 4G+ signal.
Optimize the configuration for dual SIM cards.
Optimize dual SIM card switching.
Add cellular modem MTU configuration option.
Fix TTL configuration confusion.
Correct abnormal display on the relay page.
Fix 2.4G forced to use 20MHz bandwidth setting.
Ensure AdGuard Home processes client requests after enabling bypass routing.
Resolve an issue where parental control could not control video streaming.
Ensure parental control rules prohibiting domain name/IP are effective when accessing Google Chrome.
Fix issue where WDS mode switches back to routing mode and device cannot obtain an IP address.
Remove cellular modem soft restart.
Remove ipv6 passthrough.

4.3.1 2023-05-12
SHA256: 55c03c8c1cf6b363... 🔗 share
Release notes

BUG fix

Resolved an issue where the parental control function was unable to control video streaming.
Fixed an issue where the cellular was unable to access the internet after updating its IP address.
Fixed an issue where the cellular's TTL setting was not working properly.
Resolved an issue where VPN second connection was failing.
Repaired an LED display abnormality that occurred after switching SIM cards.

Improvements

Optimized the display of the date for timed tasks.
Optimized the display of frequency band filtering in the cellular network configuration.

4.3.0 2023-04-25
SHA256: 56fb4a4ece255ad4... 🔗 share
Release notes

BUG fix:

  • GL.iNet SDK support X3000.
4.9.0 beta2 build 1027 2026-06-01
SHA256: 46f7f2bb05a3aff7... 🔗 share
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-29: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
  • 2026-06-01: Fixed an issue with incorrect log printing levels.
4.9.0 beta1 build 1024 2026-05-29
SHA256: 7d73badc694c7bed...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-29: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.9.0 beta1 build 1012 2026-05-25
SHA256: fb4ed0a4ffbcfdfa...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-16: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.8.4 beta2 build 973 2026-03-26
SHA256: f7f6be4f83206d21... 🔗 share
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for AmneziaWG obfuscation protocol.
4.8.4 beta1 build 967
SHA256: 6cbad061c3a10de6...
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for AmneziaWG obfuscation protocol.

GL-X300B Collie x300b

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.5.22 2025-04-10
SHA256: 33b6579552a0ebfc... 🔗 share
Release notes

V4.5.22

Overview

This version fixed some security vulnerabilities.

4.5.19 2024-08-26
SHA256: 97febfa2bbebb81c... 🔗 share
Release notes

V4.5.19

Overview

This version fixes some security vulnerabilities.

Supported Models

GL-X300B Collie, GL-A1300 Slate Plus, GL-B3000 Marble.

4.5.17 2024-06-07
SHA256: 203f6a660c958a66... 🔗 share
Release notes

V4.5.17

Overview

This version mainly includes security vulnerability resolutions.

Note: Version 4.x does not support the GPS feature.

Supported Models

GL-X300B Collie.

4.5.16 2024-03-29
SHA256: 0bdc822549d42bc4... 🔗 share
Release notes

V4.5.16

Overview

This release version mainly enhances network security and fixes known issues with network status detection, providing users with the option to manually add languages in the language community and the option to pre-emptively experience the new version. It is compatible with Full Cone NAT and SIP ALG features found in other routers. Optimization, bug fixing, and vulnerability repair for more vendors are shown below. Note: Version 4.x does not support the GPS feature.

Supported Models

GL-A1300 Slate Plus, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-MT3000 Beryl AX, GL-MT2500/GL-MT2500A Brume 2, GL-X300B Collie

New features

  • Reconstructed mwan3 and renamed it as kmwan. Optimized failover and load balancing, as well as network status in various scenarios.
  • Added the Security configuration page.
  • Added grayscale testing design. Added RC version subscription and upgrade.
  • Added the communityization of language packs to support manual addition.
  • Added support for IPoE, and support for configuring VLAN ID during DHCP and static dialing.
  • Added Full Cone NAT function.
  • Added the SIP ALG option.
  • Added new temperature protection setting for MTK Wi-Fi.

Improvements

  • Optimized the side route UI interaction and add the option to turn off the DHCP server itself.
  • Optimized the restart process of the relay program.
  • [Only for GL-X300B Collie] Optimized the functionality of RS485, the UI, and localization.
  • Optimized the Tailscale mechanism.
  • Updated language files and pull translation scripts.

Bug fixes

  • Fixed an issue where the interface jumped due to the incorrect change in the client's online time.
  • Fixed an issue with the TTL settings not taking effect.
  • Fixed an issue where scanning always indicated that it was in DFS when all interfaces were disabled.
  • Fixed an issue of failing to enable Wi-Fi for the first time after upgrading.
  • Fixed an issue of failing to connect to the AP due to a failure to parse IE_HT_CAP.
  • Fixed an issue where multiple parsed AllowedIPs were incorrect when parsing the uploaded WireGuard client configuration files.
  • Fixed an IP conflict issue that occured when adding a client profile to WireGuard after modifying the PeerIP of the WireGuard server configuration via SSH.
  • Fixed an issue where inbound data from non-VPN interfaces would not trigger port forwarding rules when VPN was enabled.
  • Fixed an issue where some devices from the TAP-S2S OpenVPN client would not display properly on the client page.
  • Fixed an issue where the OpenVPN server certificate may be lost after rebooting the device.
  • Fixed an issue where selecting manual mode on the MAC address page and entering the factory default MAC address on the ethernet page would result in an unsuccessful configuration even after connecting to the repeater successfully at first.
  • Fixed an issue where the network speed limit feature was still activated after enabling network speed limit, enabling network acceleration, and rebooting the device.
  • Fixed some known vulnerabilities.
3.217 2023-05-08
SHA256: 44621110f771982c... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (MIFI,X750,E750,XE300,XE300)
  2. Based on QSDK11 (AP1300)

Important bugfix

  1. Fix account error for SMTP settings.
3.216 2023-03-21
SHA256: 2068a20426a5267a... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

GL-X750 Spitz x750

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.25 2025-03-31
SHA256: c6f0d845474d3d2f... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.19 2024-08-23
SHA256: 3548e4e593347c20... 🔗 share
Release notes

V4.3.19

Overview

This version fixes some security vulnerabilities.

Supported models

Beryl (GL-MT1300), Spitz (GL-X750), Opal (GL-SFT1200).

4.3.18 2024-08-03
SHA256: 1e031af73662f633... 🔗 share
Release notes

V4.3.18

Overview

This version introduces new SIM APN support, alongside various bug fixes and security enhancements.

Supported Models

Beryl(GL-MT1300), Spitz(GL-X750V2), Opal(GL-SFT1200).

New Features

  • Added APN support for Webbing SIM cards (wbdata)(GL-X750V2).

Bug Fixes

  • Fixed the issue where the device fails to connect to the network via QMI or QCM protocols when a telecom card is inserted and IPv6 is enabled.
  • Fixed the issue of dnscrypt generating unnecessary logs on SFT1200 devices.
  • Fixed the misidentification of LAN port speed on SFT1200 devices.
  • Fixed the issue where the default luci page of SFT1200 only supports English configurations, excluding Chinese.
  • Fixed the generation of unnecessary netclash logs during the startup process.
  • Fixed dial-up failures on the modem during the dialing process when using QMI protocol, manually setting APN, and selecting PAP/CHAP authentication.
  • Fixed the issue that under European (DE) country code, there will be a high band channel (149-161), and the channel display is wrong when 20MHz bandwidth is set.
  • Fixed the problem of 2.4GHz channel display error after switching to Japan country code in luci page.
  • Fixed the issue that when GL-MT1300 long press Reset for 4-7 seconds to switch routing mode, the br-lan interface is not working.
  • Fixed the issue that the GL-X750V2 cannot ping IPV6 web site after switching IPV6 mode.
4.3.17 2024-06-07
SHA256: 184e48c6dd5befbb... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.11 2024-03-21
SHA256: 08b136d116968e5c... 🔗 share
Release notes

V4.3.11

Overview

This firmware release provides optimizations, bug fixes, and fixes for security vulnerabilities.

Supported Models

GL-AR300M,GL-AR300M16,GL-AR750,GL-AR750S,GL-B1300,GL-MT300N-V2,GL-MT1300,GL-SFT1200 and GL-X750

New features

  • Added language support for Korean.
  • (Only available on GL-X750) Added some software packages: kmod-fs-vfat, kmod-fs-ntfs, kmod-fs-ext4, e2fsprogs.

Bug fixes

  • Fixed an issue with GL-MT300N-V2 where the dip switch and the UI display were reversed.
  • Fixed an issue with GL-MT300N-V2 where wireless terminals could not obtain an address after successfully switching to the Extend and WDS modes.
  • Fixed an issue where two routers acting as the VPN server and the VPN client respectively could not automatically reconnect after disconnection due to network volatility.
  • Fixed an issue where client devices connected through an ethernet cable would not automatically reconnect after the LAN IP address was modified.
  • Fixed a conflicted that occurred with GL-SFT1200 between PPPoE protocol with VLAN ID and hardware acceleration.
  • Fixed an error that happened when a device using PPPoE protocol first switched to the Extender mode and then restored the Route mode.
  • Fixed various known vulnerabilities.
4.3.7 2023-12-22
SHA256: dc329943aa99fba6... 🔗 share
Release notes

V4.3.7

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version of firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version of firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750,MV1000).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS feature.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fi with the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.
  • Optimized VPN configuration file generation and parsing speed.

Bug fix

  • Fixed the TTL settings not taking effect when fw4 is used.
  • Fixed VPN DNS leak.

Vulnerability fix

  • Fixed a vulnerability that allowed arbitrary files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed a bypassing vulnerability where Nginx authentication could be bypassed through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users could bypass authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where accessing the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, executing arbitrary code in the process. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interfaces of the logread module, which could allow arbitrary shell commands to be executed via JSON parameters, posing a significant security threat. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which could allow arbitrary shell commands to be executed through JSON parameters, representing a significant security risk. (CVE-2023-50445)
3.217 2023-05-08
SHA256: ff062ea6f5f528e7... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (MIFI,X750,E750,XE300,XE300)
  2. Based on QSDK11 (AP1300)

Important bugfix

  1. Fix account error for SMTP settings.
3.216 2023-03-21
SHA256: 3a42762cee6135ae... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.
4.3.29 beta1 build 453 2026-05-29
SHA256: 2b024427bd75f4b9... 🔗 share
Release notes

V4.3.29

Overview

This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • 2026-05-28: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.3.29 beta1 build 451 2026-05-21
SHA256: dca8e487bbebb8a3...
Release notes

V4.3.29

Overview

This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

Bug Fixes

  • 2026-05-20: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.

GL-XE300 Puli xe300

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.3.27 2025-05-14
SHA256: 54062a62138d13a9... SHA256: 9671b723708e5dc0... 🔗 share
Release notes

V4.3.27

Overview

This version mainly fixed some known bugs.

Bug Fixes

  • Fixed the issue where the transmit power was abnormal in certain situations.
4.3.25 2025-03-31
SHA256: 2ac15c37238ec68c... SHA256: 4b9ec5d347a3e455... 🔗 share
Release notes

V4.3.25

Overview

This version fixes some security vulnerabilities.

Synchronize Updated Models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300).

4.3.18 2024-08-23
SHA256: 007f1c1fc6e44484... SHA256: 49383b1937229c4f... 🔗 share
Release notes

V4.3.18

Overview

This version fixes some security vulnerabilities.

Supported models

Slate (GL-AR750S), Creta (GL-AR750), Mudi (GL-E750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300).

4.3.17 2024-06-20
SHA256: f8e1bab04119679a... SHA256: 5ceaeed9d8e0f682... 🔗 share
Release notes

V4.3.17

Overview

This version fixes some security vulnerabilities and other bugs.

Supported models

Opal (GL-SFT1200), Beryl (GL-MT1300), Slate (GL-AR750S), Creta (GL-AR750), Shadow (GL-AR300M), Shadow (GL-AR300M16), Mango (GL-MT300N-V2), Mudi (GL-E750), Spitz (GL-X750), Puli (GL-XE300), Convexa-B (GL-B1300), Cirrus (GL-AP1300), Convexa-S (GL-S1300).

Bug fixes

  • Fixed the issue that the Web may show an error message when modifying the Maximum Number of Users or DHCP Gateway in the LAN page.
  • Fixed the issue that some disconnected Wi-Fi clients still show online in the client list.
  • Fixed the issue that the color of the online upgrade dialog is abnormal under the dark theme.
  • Fixed the issue that GL-SFT1200 can not be upgraded online.
  • Fixed the issue that the client device cannot access the Internet IPv6 address in Static IPv6 mode of GL-SFT1200.
  • Fixed some interface text errors.
4.3.16 2024-02-27
SHA256: 3af11d52ba7e9725... SHA256: b14d3e15309bc814... 🔗 share
Release notes

V4.3.16

Overview

Available for Puli (GL-XE300), this release version added support for SIM card APN, fixed bugs and vulnerabilities, and provided optimizations.

New features

  • Added a list of supported SIM card APNs (American, bics, bicsapnn).

Bug fixes

  • Fixed an issue where a network error would appear and firmware verification would continue to run after an incorrect .img firmware file was uploaded during local upgrade.
  • Fixed an issue where LAN-side PCs and wireless terminals were assigned the prefix ddxx instead of fdxx when using IPv6 NAT6 mode.
  • Fixed an issue where clearing the traffic statistics would reset the speed to zero in Clients.
  • Fixed an issue where Chinese and special characters were not supported in the Description field on the IP MAC binding page.
  • Fixed an issue in the Log page of the admin panel where the Cloud Log was empty but the exported log file had content.
  • Fixed an issue where the connection must be disconnected first when a different mobile OS (Android or Apple) was used for the USB tethering feature to function properly.
  • Fixed an issue where the PAP/CHAP authentication failed when the modem was dialed using the QMI protocol.
  • Fixed an issue where the SMS sending and forwarding function did not work.
  • Fixed an issue where an error message saying Response timed out. Please check the network environment or restart the device. would display when switching to the new IP address on the admin panel after changing the LAN IP address.
  • Fixed an issue where the hard restart button in the modem management of the admin panel was displayed abnormally.
  • Fixed an issue where the modem status was not correct after opening or refreshing the admin panel.
  • Fixed an issue where the admin panel would display an error saying Response timed out. Please check the network environment or restart the device. when opening or refreshing the admin panel.
  • Fixed an issue where the probability of ethernet on the admin panel was not displayed properly and showed garbled characters when switching ethernet to DHCP or static.

Vulnerability fixes

  • Fixed an issue where the user didn't need to sign in to the admin panel before downloading the generated log file.
4.3.7 2023-12-22
SHA256: e4a6e145a336bd45... SHA256: 8241a9c308122e7a... 🔗 share
Release notes

V4.3.7

Cautions

  • Your settings can NOT be kept when upgrading to this version from 3.x. Please backup your settings first.
  • This version of firmware does NOT include the following features:
    • File Sharing
    • Captive Portal
    • Automatic Upgrade
    • RS485
    • GPS
    • Mesh
  • This admin panel does NOT include the following languages:
    • French
    • Korean
    • Russian
  • Limited by CPU performance and storage space, this version of firmware also does NOT include Network Storage fature. (Allow users to install via plug-in after exroot)

OpenWrt Upgrade

  • Built based on OpenWrt 22.03.4 (AR300,AR750,AR750S,X300B,X750,XE300,MT300N-V2,MT1300,E750,MV1000).
  • Built based on OpenWrt 21.02.2 (B1300).
  • Built based on OpenWrt 18.06 (SFT1200).

New Features

  • Added Scheduled Tasks feature.
  • Added Overview page to display system loading and set LED.
  • Added Multi-WAN feature, allowing users to switch between failover and load balancing modes.
  • Added Drop-in Gateway feature.

Optimization

  • Refactored and optimized System Architecture.
  • Redesigned interface UI.
  • Optimized sidebar structure.
  • Refactored and optimized repeater feature.
  • Refactored and optimized VPN features.
  • Refactored and optimized clients feature.
  • Optimized Cellular Settings feature.
  • Optimized DNS feature.
  • Optimized MAC Clone feature, which has been renamed to MAC address.
  • Optimized IPv6 feature with the addition of Native mode.
  • Optimized Guest Wi-Fi with the addition of SSID Visibility option.
  • Optimized DDNS Test.
  • Optimized connections with GoodCloud.
  • Optimized VPN configuration file generation and parsing speed.

Bug fix

  • Fixed the TTL settings not taking effect when fw4 is used.
  • Fixed VPN DNS leak.

Vulnerability fix

  • Fixed a vulnerability that allowed arbitrary files to be created or modified through the API. (CVE-2023-47464)
  • Fixed an unauthorized remote code inclusion vulnerability in the webDAV file server. (CVE-2023-47463)
  • Fixed a bypassing vulnerability where Nginx authentication could be bypassed through a Lua string pattern matching vulnerability. (CVE-2023-50919)
  • Fixed an issue where users could bypass authentication or access control measures by assigning the same session ID each time they restarted. (CVE-2023-50920)
  • Fixed an issue where accessing the add_user interface in the system module could allow root access. (CVE-2023-50921)
  • Fixed a vulnerability that allowed arbitrary shell commands to be executed through carefully crafted package names. (CVE-2023-46454)
  • Fixed a path traversal vulnerability in the OpenVPN client file upload, which could lead to arbitrary file writes. (CVE-2023-46455, CVE-2023-46456)
  • Fixed a vulnerability that allowed an attacker who stole the AdminToken cookie to upload a crontab-formatted file to a specific directory and wait for it to execute, executing arbitrary code in the process. (CVE-2023-50922)
  • Fixed an injection vulnerability in the gl_system_log and gl_crash_log interfaces of the logread module, which could allow arbitrary shell commands to be executed via JSON parameters, posing a significant security threat. (CVE-2023-50445)
  • Fixed an injection vulnerability in the upgrade_online interface of the upgrade module, which could allow arbitrary shell commands to be executed through JSON parameters, representing a significant security risk. (CVE-2023-50445)
3.217 2023-05-08
SHA256: d5cfa70d2f3cfa47... SHA256: d2c206845e629f21... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (MIFI,X750,E750,XE300,XE300)
  2. Based on QSDK11 (AP1300)

Important bugfix

  1. Fix account error for SMTP settings.
3.216 2023-03-21
SHA256: 80bcd19865c2b6c7... SHA256: 187660a9cf1d960c... 🔗 share
Release notes

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.
4.8.4 beta1 build 1006 2026-06-03
SHA256: a5836eef3e343ec1... SHA256: bf28937d253a26e5... 🔗 share
Release notes

V4.8.4

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
  • Fixed the SIM card data usage statistics issue
  • 2026-06-02: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
  • 2026-06-02: Fixed the time zone synchronization issue and the default SSID error issue.
4.8.4 beta1 build 984 2026-05-25
SHA256: 0620b464db01d5ea... SHA256: 8b6e838ebc0a894a...
Release notes

V4.8.4

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
  • Fixed the SIM card data usage statistics issue
  • 2026-05-16: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.8.3 2026-03-26
SHA256: 648aa6e690049e26... SHA256: 1ece8446e491e810... 🔗 share
Release notes

V4.8.3

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
  • Fixed the SIM card data usage statistics issue
4.7.15 2025-07-28
SHA256: 5aea051625b9ddef... SHA256: f46f1fe0a1a6f1e0... 🔗 share
Release notes

V4.7.15

Overview

This version includes adjustments to enhance device security.

New Features

  • Added a global SSH toggle.

Optimization

  • Added a user privacy policy statement to the initialization wizard page.
  • Added a security warning when WiFi security is set to OPEN.
  • Optimized the network abnormal traffic protection mechanism, adding flood protection for ICMP and other protocols.
  • LuCI functionality is no longer pre-installed; users can install LuCI with one click on the advanced settings page.
  • Optimized Nginx log management, adding login and configuration change logs. Logs are automatically synchronized to Flash upon reboot.
  • Repairing cellular traffic statistics is ineffective
  • Fix that the modem cannot register for 4G network connection

GL-XE3000 Puli AX xe3000

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.8.3 2025-11-10
SHA256: ba6f76f32686e86c... 🔗 share
Release notes

V4.8.3

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience.

New Features

  • Added VPN multi-instance to support enabling multiple VPN clients simultaneously.
  • Added VPN composite policy for traffic diversion based on multiple criteria, including source interface, source MAC address, and destination domain/IP.
  • Added an option to enable or disable VPN internet access on the Clients page, which is effective only for MAC-based VPN policies.
  • Added the isolation feature between the Guest Network and the Upstream network.
  • Added HTTPS support for RTTY.
  • Added a one-click option to send logs to technical support.
  • Added IPv6 support for VPN.

Optimization

  • Refactored the Cellular function for improved performance and user interface, supporting more parameter configurations and status displays.
  • Redesigned the UI style, improved the Web Admin Panel topology, and introduced new controls to support the presentation of complex services.
  • Optimized the guidance of VPN functionality to simplify usage.
  • Optimized VPN configuration to support IPv6.
  • Optimized the export of client configuration files for the VPN Server, allowing users to manually enter the server address in the configuration file.
  • Optimized the Clients page, supporting quick setting of reserved IP addresses.
  • Optimized the Log display to support filtering by Log level, module, and keywords, as well as exporting more debugging information.
  • Optimized the GoodCloud platform's device binding functionality.
  • Optimized the display of VPN Server page status information.
  • Optimized vSIM functionality.
  • Optimized the Repeater auto-switching logic.
  • Improved the ease of use of the AstroWarp functionality.
  • Upgraded OpenVPN to version 2.6.12, support dco to improve OpenVPN performance.
  • Upgraded Dnscrypt-proxy to version 2.1.5.
  • Upgraded Stubby to version 0.4.3.
  • Upgraded Zerotier to version 1.14.1.

Bug Fixes

  • Fixed security vulnerability CVE-2025-44018
4.7.4 2025-03-17
SHA256: a518d0aebe0406f7... 🔗 share
Release notes

V4.7.4

Overview

This version introduces several new features and enhancements that improve the interface interaction for overall user experience.

Synchronize Updated Models

Puli AX(GL-XE3000), Spitz AX(GL-X3000).

New Features

  • Added device initialization wizard, including settings for administrator and WiFi password, networking connection, VPN and other core functionalities.
  • Added AstroWarp mode (Beta), allowing you to create your own network using aggregated connections and cloud gateways for a high-speed, stable network experience.
  • Added cloud account login functionality, supporting device binding to the cloud from the firmware web page.
  • Added domain name list subscription feature, supporting VPN policies and parental control through URL subscriptions for online domain name or IP list.
  • Added support for Control D DNS.
  • Added AP Isolation function.
  • Added Luci Access Restriction function.
  • Added Network Port Management page, supporting scheduled and reboot of automatic updates for Ethernet MAC, WAN/LAN port switching, and displaying network port negotiation rates.
  • Added support for NordVPN, PIA, Surfshark, Hideme, IPVanish WireGuard VPN services, along with AzireVPN registration functionality.
  • Added cellular data traffic statistics feature.

Optimization

  • Optimized the process for manually adding the WireGuard client configuration files and supporting automatic key generation.
  • Optimized the process of configuring vendor profiles for VPN clients.
  • Optimized repeater random MAC settings, supporting scheduled and reboot of automatic updates for repeater MAC.
  • Optimized the detection process for multi-WAN load network status.
  • Optimized OpenVPN Client functionality, allowing modification of configuration file names.
  • Optimized the page names in the web management panel so that the router's hostname is displayed in the browser tab.
  • Optimized the design of interface error messages and interactive elements like input dropdown lists.
  • Upgraded AdGuard Home to version 0.107.52.
  • Upgraded Tor to version 0.4.8.9.
  • Optimized the display of MCC/MNC data in Cellular settings, after scanning the BTS and Cell information pages, providing readable carrier operator names on the respective information pages.
  • Optimized NSA signal selection in Cellular settings, ensuring 5G NSA band and LTE band work together. This means that configuring 5G NSA requires you to also configure the LTE band.
  • Optimized the firmware upgrade process (manual, online, and via the cloud platform) by adding memory detection alerts to prompt users to clear memory when the device storage is insufficient.
  • Optimized eSIM functionality.
  • Optimized the reporting of cellular traffic data to the cloud platform and the SIM lock alert system.

Bug Fixes

  • Fixed an issue where the name of a wired connection in the client list was displayed as 'unknown' when the client connected to the device using both wired and wireless methods simultaneously.
  • Resolved an issue where certain mobile phones (e.g., Xiaomi 10, Huawei) could not connect via QR code when the 2.4G Guest Wi-Fi was encrypted with WPA3 or hidden.
  • Fixed an issue where port forwarding rules remained active even when the DMZ priority was set to the highest level.
  • Addressed a bug where devices in a Tailnet organization with a Tailscale email domain name randomly displayed the email addresses of other devices in the same organization.
  • Fixed an issue where the first modification of MAC mode did not take effect after a successful relay connection.
  • Resolved a problem where manually configured APN settings reverted to default after a router restart.
  • Fixed a DNS leakage issue that occurred when connecting to a VPN client via a wired network with IPv6 and Modem dialing enabled.
  • Corrected a problem where changing the password of one wireless band disconnected clients on other bands.
  • Fixed an issue where the randomized BSSID was automatically disabled after Wi-Fi configurations were modified via the cloud platform.
  • Resolved an issue where the page displayed 'Checking for channel availability' even when the selected 5G Wi-Fi channel was not a DFS channel.
  • Addressed a problem where the WAN port provided DHCP services in Drop-in Gateway mode when the 'Some devices select their own networking gateway' option was enabled.
  • Fixed an issue where IPv6 online status detection was not performed on external M.2 modules.
  • Corrected an error where the page reported an 'unknown error' when a PPPoE username or password exceeded 256 characters.
  • Fixed a bug where established SSH connections remained active even after Remote SSH was turned off.
4.4.13 2024-10-25
SHA256: b51caad4a7e42183... 🔗 share
Release notes

V4.4.13

Overview

This release mainly added eSIM and Cellular module update functions, and fixed some known bugs.

Synchronized Updated Models

Puli AX (GL-XE3000), Spitz AX (GL-X3000)

New Features

Added eSIM functionality. Added Cellular module update feature.

Bug Fixes

  • Fixed the issue where enabling parental controls and adding a schedule to disable Internet access in repeater networking prevented devices in the disabled Internet group from accessing web pages.
  • Fixed the issue where dailing with a modem failed when the protocol was set to QMI, the APN was manually configured, and the authentication method was set to PAP/CHAP.
  • Fixed the issue where the repeater could not scan for the 5GHz upstream wireless network when it was set to 20M on channel 165.
4.4.12 2024-09-25
SHA256: 2281e655fece6cfb... 🔗 share
Release notes

V4.4.12

Overview

This release mainly fixes some known issues, optimizes features and adds new feature.

Support Models

Puli AX (GL-XE3000), Spitz AX (GL-X3000)

Function Added

Added the cellular module update function.

Improvement

  • Updated Wi-Fi driver.
  • Upgrade AdGuard Home version to v0.107.46.

Bug Fixes

  • Fixed the issue that the rtty connection of cloud platform will not be disconnected after the login password is changed.
  • Fixed the issue that dialling fails due to PIN unlock failure when using multiple APNs.
  • Fixed the issue that SSH connection will not be disconnected when ports 80 and 22 are closed.
  • Fixed the issue where relay scanning for SSIDs with carriage return characters caused the relay program to crash.
  • Fixed a DNS leak issue with VPN.
  • Fixed an issue with AdGuard Home configuration errors.
  • Fixed the issue that wgclient connects to wgserver on local LAN and occasionally loses firewall rules after rebooting the device.
  • Fixed the issue that WebDAV data cannot be accessed after rebooting the device.
4.4.11 2024-08-24
SHA256: c52607a295dcd2a4... 🔗 share
Release notes

V4.4.11

Overview

This version fixes some security vulnerabilities.

Supported Models

Puli AX (GL-XE3000), Spitz AX (GL-X3000).

4.4.9 2024-06-15
SHA256: a14853f59db9f05e... 🔗 share
Release notes

V4.4.9

Overview

This version add support for Webbing SIM cards and fixes some security vulnerabilities and other bugs.

Supported models

Puli AX (GL-XE3000), Spitz AX (GL-X3000).

New features

  • Added support for Webbing SIM card, the device will now automatically set the APN to wedata for it.
  • Added the cellular auto-dialing feature when the Webbing SIM card is detected at boot-up.

Bug fixes

  • Fixed an issue that cellular network cell information was displayed incorrectly.
  • Fixed the issue that after manually disabling Tailscale and powering off the device, Tailscale will be enabled automatically when the device is rebooted.
  • Fixed the issue that after manually disabling DDNS and powering off the device, DDNS will be enabled automatically when the device is rebooted.
  • Fixed an issue where a warning was not displayed on the cellular icon on the Internet page when the cellular network could not connect to the Internet.
  • Fixed an issue that devices could not reset correctly when Tailscale was enabled.
  • Fixed an issue where uploading an OpenVPN/WireGuard client's profile name containing the character ~ would cause the upload to fail.
  • Fixed an issue that cellular network traffic statistics are displayed incorrectly.
  • Fixed an issue that WireGuard server would show the displayed offline clients as online.
  • Fixed some interface text errors.
4.4.8 2024-04-19
SHA256: 14cfdc0c46b045fc... 🔗 share
Release notes

V4.4.8

Overview

This firmware version mainly provides fixes to bugs and security vulnerabilities.

Supported Models

GL-XE3000

New Features

  • Added offline troubleshooting support for cellular connection issues.
  • Added a message about being authenticated by AT&T and T-Mobile.
  • Added support for Eiotclub APN.

Improvements

  • Upgraded Tailscale to version 1.58.2.

Bug Fixes

  • Fixed an issue where the DNS of the VPN was not shown on the DNS page when the VPN client was enabled.
  • Fixed an issue where AT&T or T-Mobile SIM cards with certain MNC or MCC codes could not connect to the internet.
  • Fixed an internet disconnection issue caused by network detection of the cellular interface.
  • Fixed an abnormal IPv6 network issue when IPv6 NAT6 used the ddxx:: prefix.
  • Fixed an issue that the PIN code did not work.
  • Fixed an issue where ICCID hexadecimal was displayed incorrectly.
  • Fixed a rare issue where the route rmnet_mhi0 would not update.
  • Fixed an issue where DNS resolution would not work if the Block Non-VPN Traffic option was enabled when using proxy mode based on destination domain name or IP.
  • Fixed an issue where repeater would fail if all Wi-Fi networks were disabled.
  • Fixed an issue where cloud disconnection after turning on AdguardHome or configuring DNS.
  • Fixed some known vulnerabilities.
4.4.4 2023-12-09
SHA256: cbca8e7a2b4838e6... 🔗 share
Release notes

BUG fix

  • Add an explanation for the 4G+ display.
  • Fixed some shell injection vulnerabilities
4.4.3 2023-10-26
SHA256: a30156f5af4d7e49... 🔗 share
Release notes

BUG fix

  • Fixed modem status monitor.
  • Fixed the issue of retaining configuration changes to the IP address during module upgrades without requiring a full update.
  • Optimize the cellular dialing function.
  • Add an explanation for the 4G+ display.
  • Modify the repeater display to show 'Repeater (Wi-Fi as WAN)'.
  • Fixed cloud memory leaks.
4.4.2 2023-09-08
SHA256: 754c5f6fb9fab2f7... 🔗 share
Release notes

BUG fix

  • Add the ability to lock onto a specific cell tower.
  • Add real-time display of signal commands.
  • Add the Orange configuration module.
  • Fixed the error in displaying LTE bandwidth.
  • Fixed the issue where the VERIZON APN module configuration fails to take effect.
  • Optimize the tower configuration.
  • Resolve the signal strength display error.
  • Introduce the signal upload function to the cloud platform.
  • Ensure compatibility with time-consuming AT commands.
  • Fixed Tmobile restart dial exception.
4.4.1 2023-07-07
SHA256: cf172b974c4ab165... 🔗 share
Release notes

BUG fix

  • Add display for 5G NSA, 5G SA, and 4G+.
  • Fix the issue of incorrect signal strength in NSA mode.
  • Fix the issue where the module incorrectly displays dl_bandwidth and ul_bandwidth.
  • Optimized Cellular settings interface interaction.
  • Fix after a qos limit is set, the limit cannot be canceled.
4.4.0 2023-06-05
SHA256: b5a08b21577d93a8... 🔗 share
Release notes

V4.4.0

  • first firmware
4.9.0 beta2 build 1027 2026-06-01
SHA256: d2634836a0d407b3... 🔗 share
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-29: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
  • 2026-06-01: Fixed an issue with incorrect log printing levels.
4.9.0 beta1 build 1012 2026-05-25
SHA256: 8e23d186cdaf81f1...
Release notes

V4.9.0

Cautions

  • Due to a comprehensive redesign of the Parental Control feature in V4.9.0, existing configurations for this feature will not be preserved during the upgrade. You will need to reconfigure your settings after the update. Please back up your settings first.
  • With the introduction of multi-select configuration and intra-tunnel failover for VPN tunnels in V4.9.0, the inter-tunnel failover feature has been removed. When upgrading with configuration retention, the Kill Switch will be enabled by default in all tunnels. Please back up your settings first.

Overview

This version introduces several new features and enhancements that improve the interface interaction for the overall user experience. This is a beta firmware, which has only undergone basic testing. Please use with caution and contact support@gl-inet.com if you encounter any problems.

New Features

  • Added support for DPI (Deep Packet Inspection), providing data statistics, content filtering, and intelligent QoS (Quality of Service).
  • Added SQM (Smart Queue Management) to intelligently optimize network queues, reduce latency and jitter.
  • Added multi-node selection for VPN tunnels, with automatic failover in case of node failure.
  • Added support for PureVPN and Windscribe services under the WireGuard protocol.
  • Added an option to enable or disable specific profile configurations in WireGuard Server.
  • Added support for creating dedicated networks for IoT devices.
  • Added Cellular Profile management and online APN database updates.
  • Added ACL (Access Control List) functionality to control network traffic based on rules such as protocol, source IP address, destination IP address, and port number.
  • Added support for running the router as a Tailscale exit node and an IP masquerade option.
  • Added an option to disable automatic detection and cancel in-progress firmware download.
  • Added an automatic cleanup function for offline clients on the Client page.
  • Added support for the AmneziaWG 2.0 obfuscation protocol.
  • Address Reservation now supports setting a custom Hostname.

Optimization

  • Redesigned the VPN functionality, optimizing core interaction flows and visual design for a more intuitive interface and smoother operation.
  • Redesigned the Wireless interface by simplifying the layout and unifying the visual hierarchy, making it cleaner and more intuitive.
  • Optimized the Cellular interface by integrating cellular features, improving the user experience.
  • Optimized encrypted DNS functionality, supporting DoH, DoT, and DoQ encryption methods, along with more DNS provider options, and added the ability to manually configure encrypted DNS servers.
  • Improved the Parental Control feature by streamlining the setup process, supporting basic device management, internet time control, and content filtering.
  • Upgraded Tailscale to version 1.92.5.
  • Upgraded AdGuard Home to version 0.107.73.
  • VPN Client now supports batch selection and deletion of configurations.
  • Improved the Port Forwarding feature to automatically perform one-to-one mapping for external and internal port ranges.
  • When IPv6 is enabled, IPv6 connection status tracking in Multi-WAN is activated automatically.

Bug Fixes

  • 2026-05-16: Update the dnsmasq component to version 2.92, incorporating upstream CVE fixes.
4.8.4 beta2 build 973 2026-03-26
SHA256: 77d6a9b8cc94b5eb... 🔗 share
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for the AmneziaWG 2.0 obfuscation protocol.
4.8.4 beta2 build 973 2026-03-26
SHA256: b1e409f30a21b926...
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for AmneziaWG obfuscation protocol.
4.8.4 beta1 build 967
SHA256: 5f5eb2e9ae4ffbc5...
Release notes

V4.8.4

Overview

This version mainly fixed some known bugs.

Optimization

  • Optimized the AstroWarp feature design, allowing users to connect to the router using an access code without binding account or complex configurations. Users can also manage connections and top up plans directly on the router interface.

New Features

  • Added support for the AmneziaWG 2.0 obfuscation protocol.

microuter-N300 n300

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
3.218 2024-07-30
SHA256: 3a5a43ab7e85332c... 🔗 share
Release notes

V3.218

Overview

This firmware release provides fixes to various bugs and security vulnerabilities.

Supported Models

Velica (GL-B2200), Brume (GL-MV1000), Brume-W (GL-MV1000W), Microuter (GL-USB150), microuter-N300, GL-SF1200.

Bug fixes

  • Fixed an issue that the client device of the router could not get an IP address if the router as a VPN client disconnects and reconnects with an OpenVPN server in S2S-TAP mode.
3.216 2023-03-21
SHA256: ab284dd45f5c2b0c... 🔗 share
Release notes

System

  1. Based on openwrt 19.07.8 (AR150,MIFI,AR300M,USB150,N300,AR750,AR750S,X750,E750,XE300,MT1300,MT300N-V2,MV1000)
  2. Based on QSDK11 (B1300,S1300,AP1300,B2200,AX1800)
  3. Based on Siflower SDK (SF1200,SFT1200)

Security

  1. Fixed shell injection vulnerabilities.

New features

  1. Support upgrade to sdk4.x.

Important bugfix

  1. Fixed SF1200/SFT1200 VPN data leaks.
  2. Fixed MT300N-V2 switch does not reset after the network is restarted.
  3. Fixed X750 wireless initialization exception.
  4. Fixed B2200 WiFi mac error.
  5. Fixed B2200 MESH clients display error.
  6. Fixed B2200 MESH link instability.
  7. Fixed B2200 MESH status LED display error.
  8. Fixed B2200 MESH network failure after the upgrade.
  9. Fixed B2200 MESH sub-router web error message.
  10. Fixed AX1800 USB output is powered off because the manual modem reset.
  11. Fixed Wireguard client reconnect failure in some scenarios.
  12. Fixed Error occurs when the wireguare client name contains spaces.

KVM over IP Firmware

GL-RM1 Comet rm1

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
1.9.0 2026-04-29
SHA256: 761ecb0fbc4b49c7... 🔗 share
Release notes

New Features

  1. Delay mode configuration: Users can customize the device’s delay mode.

  2. Language support: Added Japanese language support.

  3. Function expansion: Added support for the third-party feature Netbird.

  4. Screen feature: Allow custom on-screen display settings.

  5. Enterprise network support: Added compatibility with enterprise encrypted Wi-Fi.

  6. Privacy protection: Added privacy screen loop-out feature.

  7. Mouse operation optimization: Added an option to swap left and right mouse buttons.

  8. Beta Program: Users can now join the beta program to test upcoming firmware features.

  9. OCR function: Added automatic text recognition, limited to certain languages.

Bug Fixes

  1. ZeroTier connection: Fixed the issue where the device could not be accessed in certain cases when ZeroTier was enabled.

Optimizations

  1. Connection stability: Improved the issue where disconnections might occur during long-session access via the GLKVM app or glkvm.com.

  2. Timezone settings: Allow timezone configuration by city.

  3. Login security: Adjusted login token validity from permanent to 12 hours after remote session ends.

  4. Virtual device toggle: Device restart is no longer required when enabling or disabling virtual media and related functions; MSD is now disabled by default and requires manual activation.

  5. Log security: Added sensitive data masking for system logs.

  6. Screen corruption fix: Fixed an issue where screen corruption might occur when using the maximum bitrate with WebRTC FEC (Pion).

1.8.2 2026-03-20
SHA256: 96bf7852bb7b7889... 🔗 share
Release notes

Optimizations and Fixes

  • Fixed network issues: Optimized the NIC autonegotiation mechanism to resolve the issue where the system could not automatically switch to 100 Mbps speed in specific environments, improving network stability.

  • Enhanced access security: Serial port login now requires password authentication (defaults to the firmware password) to prevent unauthorized access and protect device security.

  • Firmware signature verification: Added firmware signature to ensure firmware integrity and authenticity.

1.8.1 2026-03-16
SHA256: d5c649d85256e06a... SHA256: 9893c95cfb33fe6d... 🔗 share
📝 Re-signed by GL.iNet with digital signature (2026-03-20)
Release notes

New Features

  • EDID Compatibility: Added two EDID configurations (1600x900 and 1080P@120Hz) to improve compatibility with display devices.

Bug Fixes

  • Resolution Compatibility: For devices that do not support the 1680x1050 resolution, the system will automatically fall back to 1680x1048.

  • Audio Quality: Fixed issues with poor microphone sound quality and intermittent speaker audio.

  • Display Artifact: Resolved occasional minor screen artifacts on RM1PE/RM10/RM10RC when switching resolutions.

  • Time Synchronization: Fixed a bug where RM1/RM1PE failed to trigger NTP time synchronization after Ethernet hot-plug.

  • Startup Speed: Fixed slow service startup in offline environments, reducing boot time.

Improvements

  • Reset Optimization: Cloud binding information will be removed after firmware reset.

  • Adapter Compatibility: Improved compatibility for VGA‑to‑HDMI adapters.

  • Image Quality: Optimized image processing logic in Smart mode to enhance user experience under poor network conditions.

1.8.0 2026-01-30
SHA256: 17ac8bfbe002e4d7... SHA256: 2b890ce0e68de6d3... 🔗 share
📝 Re-signed by GL.iNet with digital signature (2026-03-20)
Release notes

New Features

Network Connectivity: Added support for Zerotier.

Security & Management: Added support for modifying TLS certificates.

Protocol & Video Quality:

  • Added WebRTC FEC (Forward Error Correction) mode to enhance performance in poor network conditions.

  • Added an option for lossless 20Mbps bitrate.

View & Control:

  • Added a view settings feature with three display modes, which users can adjust as needed.

  • Added the key-holding function for keys on the virtual keyboard.

  • Added keyboard compatibility for different operating systems, with support for swapping the Cmd and Ctrl keys.

  • Added the “Key Release Immediately” setting (Bad Link Mode), recommended for use in weak network conditions.

Configuration: Added a search function in the console for quickly finding configuration options.

Optimizations

Transmission Performance:

  • Optimized network stability and improved the smoothness of the video stream.

User Interaction:

  • Optimized multiple UI display issues.

System & Network:

  • Upgraded Tailscale to version 1.92.5.

  • Added support for configuring MSD Vendor and Microphone names in the device spoofing feature.

Bug Fixes

Fixed the issue where WoL reported false errors on devices such as GL-RM10 when Wi-Fi is disabled.

Fixed the issue where theme and language settings failed to synchronize across different access clients.

Fixed an issue where MSD Vendor-related configurations did not take effect.

Fixed an issue where the right Shift key on some keyboards would not respond when pressed.

Fixed an issue where the device IP was not immediately updated on the cloud management page after an IP change.

SSH connections are now prohibited before the system initialization is complete.

1.7.2 2025-11-28
SHA256: d232a20d7d22fd19... SHA256: 6044860b839b7ba7... 🔗 share
📝 Re-signed by GL.iNet with digital signature (2026-03-20)
Release notes

This release focuses on new features, bug fixes, and enhancements to improve system stability, security, and user experience.

New Features

  • Support for modifying the device hostname directly in the UI.
  • Support for using external USB drives as expanded storage devices.
  • Support for unmuting the microphone via a hotkey.
  • Support for adapting to the cloud-based video wall functionality.
  • Support for preserving SSH keys during system upgrades.
  • Added the Smart Mode into Video Mode, enhancing the experience in weak network conditions.
  • Support for binding to the Cloud service via a dynamic code

Optimizations & Updates

  • Upgraded Tailscale to version 1.88.3.
  • Enhanced password security policy to prevent brute-force attacks (e.g., IP ban after 10 consecutive failed attempts).
  • Updated VID/PID to GL.iNet official VID/PID
  • Optimized microphone noise issue

Bug Fixes

  • Resolved an issue where the MQTT client frequently reconnected, improving connection stability.
  • Fixed a problem where the eth0 interface could not obtain an IPv6 RA address after enabling Tailscale.
  • Fixed ntp issue
  • Fixed other known issues
1.5.0 2025-09-09
SHA256: 690e525f7dc3c6da... SHA256: 76c123881da5bd83... 🔗 share
📝 Re-signed by GL.iNet with digital signature (2026-03-20)
Release notes

Release Notes

V1.5.0

Overview

This version introduces several new features and fixes known bugs to improve the interface interaction for the overall user experience.

New Features

  • Added support for remote access via a browser.
  • Added support for private deployment of cloud services.

Bug Fixes

  • Fixed some known bugs.
1.4.2 2025-08-18
SHA256: b2e4dc8892bf5854... SHA256: 35079a6f8eb729bd... 🔗 share
📝 Re-signed by GL.iNet with digital signature (2026-03-20)
Release notes

New Features

  • Added Exit Node functionality to the App Center Tailscale

  • Supports static configuration

  • Supports changing device time zone

  • Added Direct H.264 transmission mode

  • Device Identity can be changed

  • Supports microphone audio transmission

Optimizations

  • Shows device model in version number

  • Modified common shortcut keys

  • Optimized UI effects of the pageBug

Fixes

  • Fixed known issues
1.3.1 2025-07-07
SHA256: 02b1184884e82b95... SHA256: 465f6b8e4d009504... 🔗 share
📝 Re-signed by GL.iNet with digital signature (2026-03-20)
Release notes

Optimization:

  1. Improve device compatibility

Bug Fixes:

  1. Fixed known issues

GL-RM10 Comet Pro rm10

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
1.9.1 2026-05-18
SHA256: 8cc3fd0c309ff652... 🔗 share
Release notes

New Features

  • Delay mode configuration: Users can customize the device's delay mode.

  • Language support: Added Japanese language support.

  • Function expansion: Added support for the third-party feature Netbird.

  • Display settings: Allow customizing the screen display via the web console.

  • Enterprise network support: Added compatibility with enterprise encrypted Wi-Fi.

  • Privacy protection: Added privacy screen loop-out feature.

  • Mouse operation optimization: Added an option to swap left and right mouse buttons.

  • Beta program: Users can now join the beta program to test upcoming firmware features.

  • OCR function: Added automatic text recognition, limited to certain languages.

  • Screen function: Added quick configuration support for applications such as Tailscale and Netbird.

Bug Fixes

  • ZeroTier connection: Fixed the issue where the device could not be accessed in certain cases when ZeroTier was enabled.

Optimizations

  • Connection stability: Improved the issue where disconnections might occur during long-session access via the GLKVM app or glkvm.com.

  • Timezone settings: Allow timezone configuration by city.

  • Login security: Adjusted login token validity from permanent to 12 hours after remote session ends.

  • Virtual device toggle: Device restart is no longer required when enabling or disabling virtual media and related functions; MSD is now disabled by default and requires manual activation.

  • Log security: Added sensitive data masking for system logs.

  • Screen corruption fix: Fixed an issue where screen corruption might occur when using the maximum bitrate with WebRTC FEC (Pion).

1.8.1 2026-03-20
SHA256: eed673c463b1aca6... 🔗 share
Release notes

New Features

  • EDID Compatibility: Added two EDID configurations (1600x900 and 1080P@120Hz) to improve compatibility with display devices.

Bug Fixes

  • Resolution Compatibility: For devices that do not support the 1680x1050 resolution, the system will automatically fall back to 1680x1048.

  • Audio Quality: Fixed issues with poor microphone sound quality and intermittent speaker audio.

  • Display Artifact: Resolved occasional minor screen artifacts when switching resolutions.

  • Startup Speed: Fixed slow service startup in offline environments, reducing boot time.

Improvements

  • Reset Optimization: Cloud binding information will be removed after firmware reset.

  • Adapter Compatibility: Improved compatibility for VGA‑to‑HDMI adapters.

  • Image Quality: Optimized image processing logic in Smart mode to enhance user experience under poor network conditions.

1.8.0 2026-03-20
SHA256: 323822beebf80222... 🔗 share
Release notes

New Features

Network Connectivity: Added support for Zerotier.

Security & Management: Added support for modifying TLS certificates.

Protocol & Video Quality:

  • Added WebRTC FEC (Forward Error Correction) mode to enhance performance in poor network conditions.
  • Added an option for lossless 20Mbps bitrate.

View & Control:

  • Added a view settings feature with three display modes, which users can adjust as needed.
  • Added the key-holding function for keys on the virtual keyboard.
  • Added keyboard compatibility for different operating systems, with support for swapping the Cmd and Ctrl keys.
  • Added “Key Release Immediately” setting (Bad Link Mode), recommended for use in weak network conditions.

Configuration: Added a search function in the console for quickly finding configuration options.

Optimizations

Transmission Performance:

  • Optimized network stability and improved the smoothness of the video stream.

User Interaction:

  • Optimized multiple UI display issues.

System & Network:

  • Upgraded Tailscale to version 1.92.5.
  • Added support for configuring MSD Vendor and Microphone names in the device spoofing feature.

Bug Fixes

  • Fixed the issue where theme and language settings failed to synchronize across different access clients.
  • Fixed an issue where MSD Vendor-related configurations did not take effect.
  • Fixed an issue where the right Shift key on some keyboards would not respond when pressed.
  • Fixed an issue where the device IP was not immediately updated on the cloud management page after an IP change.
  • SSH connections are now prohibited before the system initialization is complete.
  • Fixed an issue where Wake-on-LAN (WoL) would incorrectly report an error when Wi-Fi was disabled.
1.7.2 2026-03-20
SHA256: b1d053eb17b0986c... 🔗 share
Release notes

This version includes issue fixes aimed at improving system stability, security, and user experience.

Bug Fixes

  • Fixed an issue where the KVM would wake up the display every 5 minutes when the controlled device was powered off or in sleep mode.
  • Fixed an issue where Wi-Fi could not be detected in certain scenarios.
1.7.0 2026-03-20
SHA256: 983d4f726fd4aad1... 🔗 share
Release notes

This release focuses on new features, bug fixes, and enhancements to improve system stability, security, and user experience.

New Features

  • Support modifying the device hostname directly in the UI.
  • Support using external USB drives as expanded storage.
  • Support unmuting the microphone via a hotkey.
  • Support the cloud-based video wall functionality.
  • Support preserving SSH key during system upgrades.
  • Support viewing HDMI, USB connection status, and network status on the touchscreen.
  • Support previewing the controlled computer’s screen on the touchscreen.

Optimizations & Updates

  • Upgrade Tailscale to version 1.90.4.
  • Enhance password security policy to prevent brute-force attacks (e.g., IP ban after 10 consecutive failed attempts).
  • Update VID/PID to GL.iNet official VID/PID
  • Optimize microphone noise issue
  • Support sliding left to right on the touchscreen to return to the home screen.

Bug Fixes

  • Fix the issue where the MQTT client frequently reconnected, improving connection stability.
  • Fix the issue where the eth0 interface cannot obtain an IPv6 RA address after enabling Tailscale.
  • Fix ntp issue
  • Fix other known issues
1.6.1 2026-03-20
SHA256: 836947c4da880a79... 🔗 share
1.8.2 2026-03-20
SHA256: 978a8768ec0ee38d... 🔗 share
Release notes

Optimizations and Fixes

  • Fixed network issues: Optimized the NIC autonegotiation mechanism to resolve the issue where the system could not automatically switch to 100 Mbps speed in specific environments, improving network stability.

  • Enhanced access security: Serial port login now requires password authentication (defaults to the firmware password) to prevent unauthorized access and protect device security.

  • Firmware signature verification: Added firmware signature to ensure firmware integrity and authenticity.

1.9.1 2026-05-18
SHA256: ba992523dc1ab619... 🔗 share
1.9.1 2026-05-12
SHA256: be6082ab66e03b0f...
1.7.1 2025-12-30
SHA256: e372bbaf7e4e03ed... 🔗 share
1.6.2 2025-11-03
SHA256: 6e89dbc1bef313d4... 🔗 share
1.6.0 2025-10-05
SHA256: 76f6f89a589a9aad... 🔗 share

GL-RM10RC Comet 5G rm10rc

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
1.9.1 2026-06-01
SHA256: 187058c59a52cf3a... 🔗 share
Release notes

New Features

  • Latency mode: Users can customize the device's latency mode.

  • Language support: Added Japanese language support.

  • Function expansion: Added support for the third-party feature Netbird.

  • Display settings: Allow customizing the screen display via the web console.

  • Enterprise network support: Added compatibility with enterprise encrypted Wi-Fi.

  • Privacy protection: Added privacy screen loop-out feature.

  • Mouse operation: Added an option to swap left and right mouse buttons.

  • Beta program: Users can now join the beta program to test upcoming firmware features.

  • OCR function: Added automatic text recognition, limited to certain languages.

  • Screen function: Added quick configuration support for applications such as Tailscale and Netbird.

Bug Fixes

  • ZeroTier connection: Fixed the issue where the device could not be accessed in certain cases when ZeroTier was enabled.

Optimizations

  • Connection stability: Optimized occasional disconnections during long-session access via the GLKVM app or glkvm.com.

  • Timezone settings: Allow timezone configuration by city.

  • Login security: Adjusted login token validity from permanent to 12 hours after remote session ends.

  • Virtual device toggle: Device restart is no longer required when enabling or disabling virtual media and related functions; MSD is now disabled by default and requires manual activation.

  • Log security: Added sensitive data masking for system logs.

  • Screen corruption fix: Fixed an issue where screen corruption might occur when using the maximum bitrate with WebRTC FEC (Pion).

1.8.2 2026-03-26
SHA256: 12d64c198c07db91... 🔗 share
Release notes

Optimizations

  • Enhanced access security: Serial port login now requires password authentication (defaults to the firmware password) to prevent unauthorized access and protect device security.

  • Firmware signature verification: Added firmware signature to ensure firmware integrity and authenticity.

  • Optimized the NIC autonegotiation mechanism to resolve the issue where the system could not automatically switch to 100 Mbps speed in specific environments, improving network stability.

Bug Fixes

  • Fixed an issue where the screen preview would turn black when switching web page resolution.

  • Fixed known issues related to APN settings.

1.8.1 2026-03-13
SHA256: 3e017090a4d163b8... 🔗 share
Release notes

New Features

  • Added support for modifying TLS certificates

  • Added WebRTC FEC (Forward Error Correction) mode to improve user experience under weak network conditions

  • Added a lossless 20Mbps bitrate option

  • Preserved microphone mute panel status

  • Added search functionality to the panel for quick configuration lookup

  • Added view settings with three display modes, which can be adjusted according to user needs

  • Added “Instant Key Release” setting (Bad Link Mode), recommended for weak network conditions

  • Added key hold function; long-pressing on the virtual keyboard is now recognized as a sustained hold state

  • Added support for unmuting the microphone via shortcut keys

  • Improved keyboard compatibility across different operating systems, supporting swapping between Cmd and Ctrl keys

  • Added configuration support for MSD Vendor and Microphone names in the device spoofing function

  • Swipe left on the screen to access the screen preview function

  • Added support for the cloud screen wall function

  • Added support for using USB drives as expanded storage

  • Added two EDID configurations (1600x900 and 1080P@120Hz) to improve compatibility with display devices

  • Added an IPv6 firewall for cellular networks, enabled by default

  • Added support for Zerotier

Bug Fixes

  • Fixed some known bugs

Improvements

  • Firmware reset will now remove cloud binding information

  • Upgraded Tailscale to the latest version 1.92.5

  • SSH keys can be preserved during upgrades

  • Improved device stability and display smoothness

  • Optimized multiple UI display issues

  • Preserved Fingerbot press duration settings, which are not cleared after restart

  • Optimized image processing logic in Smart mode to improve user experience under poor network conditions

  • Improved compatibility for VGA‑to‑HDMI adapters

1.6.2 2026-01-23
U-Boot (.img) archived
SHA256: f7e56fcc8f479303... 🔗 share
📝 Removed from GL.iNet download site on 2026-03-26
1.8.0 2026-02-06
SHA256: c1a8389bbc990fb9... SHA256: b737573354039c25... 🔗 share
📝 Removed from GL.iNet download site on 2026-03-26
1.6.2 2026-01-12
SHA256: 99547a267d0ac516... SHA256: 7152ee5c66aa02c0... 🔗 share
📝 Removed from GL.iNet download site on 2026-03-26

GL-RM1PE Comet PoE rm1pe

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
1.9.1 2026-05-12
SHA256: 947d06b356998dc8... 🔗 share
Release notes

New Features

  • Delay mode configuration: Users can customize the device's delay mode.

  • Language support: Added Japanese language support.

  • Function expansion: Added support for the third-party feature Netbird.

  • Mouse operation optimization: Added an option to swap left and right mouse buttons.

  • Beta Program: Users can now join the beta program to test upcoming firmware features.

  • OCR function: Added automatic text recognition, limited to certain languages.

Bug Fixes

  • ZeroTier connection: Fixed the issue where the device could not be accessed in certain cases when ZeroTier was enabled.

Optimizations

  • Connection stability: Improved the issue where disconnections might occur during long-session access via the GLKVM app or glkvm.com.

  • Timezone settings: Allow timezone configuration by city.

  • Login security: Adjusted login token validity from permanent to 12 hours after remote session ends.

  • Virtual device toggle: Device restart is no longer required when enabling or disabling virtual media and related functions; MSD is now disabled by default and requires manual activation.

  • Log security: Added sensitive data masking for system logs.

  • Screen corruption fix: Fixed an issue where screen corruption might occur when using the maximum bitrate with WebRTC FEC (Pion).

1.8.2 2026-03-20
SHA256: b1b6ef1a7683da42... 🔗 share
Release notes

New Features

  • EDID Compatibility: Added two EDID configurations (1600x900 and 1080P@120Hz) to improve compatibility with display devices.

Bug Fixes

  • Resolution Compatibility: For devices that do not support the 1680x1050 resolution, the system will automatically fall back to 1680x1048.

  • Audio Quality: Fixed issues with poor microphone sound quality and intermittent speaker audio.

  • Display Artifact: Resolved occasional minor screen artifacts when switching resolutions.

  • Time Synchronization: Fixed a bug where NTP time synchronization failed to be triggered after Ethernet hot-plug.

  • Startup Speed: Fixed slow service startup in offline environments, reducing boot time.

  • Fixed network issues: Optimized the NIC autonegotiation mechanism to resolve the issue where the system could not automatically switch to 100 Mbps speed in specific environments, improving network stability.

Improvements

  • Reset Optimization: Cloud binding information will be removed after firmware reset.

  • Adapter Compatibility: Improved compatibility for VGA‑to‑HDMI adapters.

  • Image Quality: Optimized image processing logic in Smart mode to enhance user experience under poor network conditions.

  • Enhanced access security: Serial port login now requires password authentication (defaults to the firmware password) to prevent unauthorized access and protect device security.

  • Firmware signature verification: Added firmware signature to ensure firmware integrity and authenticity.

1.8.0 2026-01-30
SHA256: d6319938f0236ffe... SHA256: cd4e3e22495e5211... 🔗 share
📝 Re-signed by GL.iNet with digital signature (2026-03-20)
Release notes

New Features

Network Connectivity: Added support for Zerotier.

Security & Management: Added support for modifying TLS certificates.

Protocol & Video Quality:

  • Added WebRTC FEC (Forward Error Correction) mode to enhance performance in poor network conditions.
  • Added an option for lossless 20Mbps bitrate.

View & Control:

  • Added a view settings feature with three display modes, which users can adjust as needed.
  • Added the key-holding function for keys on the virtual keyboard.
  • Added keyboard compatibility for different operating systems, with support for swapping the Cmd and Ctrl keys.
  • Added “Key Release Immediately” setting (Bad Link Mode), recommended for use in weak network conditions.

Configuration: Added a search function in the console for quickly finding configuration options.

Optimizations

Transmission Performance:

  • Optimized network stability and improved the smoothness of the video stream.

User Interaction:

  • Optimized multiple UI display issues.

System & Network:

  • Upgraded Tailscale to version 1.92.5.
  • Added support for configuring MSD Vendor and Microphone names in the device spoofing feature.

Bug Fixes

  • Fixed the issue where theme and language settings failed to synchronize across different access clients.
  • Fixed an issue where MSD Vendor-related configurations did not take effect.
  • Fixed an issue where the right Shift key on some keyboards would not respond when pressed.
  • Fixed an issue where the device IP was not immediately updated on the cloud management page after an IP change.
  • SSH connections are now prohibited before the system initialization is complete.
1.7.1 2025-12-05
SHA256: e9a7c32ccb3bcaea... SHA256: 41862b27342ef335... 🔗 share
📝 Re-signed by GL.iNet with digital signature (2026-03-20)
Release notes

This release focuses on new features, bug fixes, and enhancements to improve system stability, security, and user experience.

New Features

  • Support for modifying the device hostname directly in the UI.
  • Support for using external USB drives as expanded storage devices.
  • Support for unmuting the microphone via a hotkey.
  • Support for adapting to the cloud-based video wall functionality.
  • Support for preserving SSH keys during system upgrades.
  • Added the Smart Mode into Video Mode, enhancing the experience in weak network conditions.
  • Support for binding to the Cloud service via a dynamic code

Optimizations & Updates

  • Upgraded Tailscale to version 1.88.3.
  • Enhanced password security policy to prevent brute-force attacks (e.g., IP ban after 10 consecutive failed attempts).
  • Updated VID/PID to GL.iNet official VID/PID
  • Optimized microphone noise issue

Bug Fixes

  • Resolved an issue where the MQTT client frequently reconnected, improving connection stability.
  • Fixed a problem where the eth0 interface could not obtain an IPv6 RA address after enabling Tailscale.
  • Fixed ntp issue
  • Fixed other known issues
1.5.1 2025-08-18
SHA256: 03306cb275fdfa81... SHA256: a6ae5f09f5cf1198... 🔗 share
📝 Re-signed by GL.iNet with digital signature (2026-03-20)
Release notes

New Features

  • Added Exit Node functionality to the App Center Tailscale

  • Supports static configuration

  • Supports changing device time zone

  • Added Direct H.264 transmission mode

  • Device Identity can be changed

  • Supports microphone audio transmission

  • Supports KVM cloud remote access

Optimizations

  • Shows device model in version number

  • Modified common shortcut keys

  • Optimized UI effects of the pageBug

Fixes

  • Fixed known issues

IoT Firmware

GL-S10 s10

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
2.3.1 2025-07-02
SHA256: 1c365e1ce55d079c... 🔗 share
2.0.8 2025-07-02
SHA256: 444d13fa0d1f8ba1... 🔗 share
3.0.3 2025-07-02
SHA256: 9e18ccca28e7fb26... 🔗 share
2.1.2 2025-07-02
SHA256: e802824cf2092d82... 🔗 share

GL-S20 (BLE Firmware) s20ble

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
1.1.0 2025-07-02
SHA256: 1409f23fb22ddbe6... 🔗 share
Release notes

V1.1.0

Overview

This version mainly adds the function of Bluetooth and reporting data, fixes the known network connection problem, provides the option of Bluetooth scanning and filtering repeatedly, and the function of reporting data in CBOR format.

New features

  • Add duplicate filter function.
  • Add report CBOR data format.
  • Add basic information function of reporting device.
  • Add MQTT advanced configuration options

##Bug fixes

  • Fix stop wifi case problem when connecting wifi ap.
  • Fix Trigger button delay problem.
  • Fix led display problem.
1.0.0 2025-07-02
SHA256: c65187640f23fb98... 🔗 share
Release notes

V1.0.0-R3 - July 15,2024

Features

    1. Basic network features a. DHCP/static protocols b. IPv4/IPv6 c. Failover feature
  1. BLE features a.Support scan Legacy advertising packets b.Support scan extended advertising packets c.Support scan periodic advertising packets
  2. System features a. System overview b. Time zone/NTP server configuration c. Firmware upgrade d. Log e. Reboot f. System backup and restore g. Change admin password h. Reset the firmware

GL-S20 (Thread Firmware) s20otbr

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
2.0.0 2024-11-04
SHA256: 3a295054da54e35c... 🔗 share
Release notes

V2.0.0-R1

Overview

This version has some new features and fixes some known issues about Thread. It also improves the performance of the system, and the following describes the specific updates.

New Features

  • Supported upgrading each other between Thread firmware and Bluetooth firmware.
  • Supported log file generation.
  • Added LED indicator control.
  • Supported custom commissioner credential.

Improvements

  • Upgraded to ESP-IDF-v5.1.3.
  • Reduced some unneccessary logs output.

Bug fixes

  • Fixed thread role not upgrading to router.
  • Fixed CoAP data packets issue.
  • Fixed some issues related to repeater.
1.0.5 2023-10-11
SHA256: 2d110a15bd62afb1... 🔗 share
Release notes

V1.0.5 - Sep 10,2023

1.add hardware version adaption 2.add http fetch headers error exist handle

2.0.1 2025-07-02
SHA256: 587493e78fa30c48... 🔗 share
Release notes

V2.0.1-B1

Overview

Compared to v2.0.0-R1, this version added Openthread REST API and can access to Home Assistant.

GL-S200 s200

Extracted firmware — not officially published by GL.iNet. These images were reconstructed from factory-installed router partitions. No upstream checksum exists for verification. Use only if you need to restore the exact factory-installed version. Full details
4.7.0 2024-12-24
SHA256: 2a5988db5d49d743... SHA256: fd19345989587111... 🔗 share
Release notes

v4.7.0-0500

WARNING

Due to some known issues, some users may not be able to upgrade online from v4.1.5-0400. Please visit the Firmware Centre to download the latest firmware for a local upgrade.

Overview

This version introduces several new features and enhancements that improve the interface interaction for overall user experience.

New features

  • Added Ethernet Pre-Set Up.
  • Added Thread Devices page and enhanced network diagonstic features.
  • Added a button to switch from the Router role to the Leader role.
  • Added Backbone Interface configuration wizard.
  • Added random Thread credentials.

Improvements

  • Updated RouterSDK to v4.7, supporting GoodCloud 3.0 and newer versions.
  • Updated OpenThread version based on Simplicity SDK v2024.6.1.
4.1.5 2024-03-12
SHA256: 3fbddeaa66f6a350... SHA256: 02601715a7c4a827... 🔗 share
Release notes

V4.1.5-0400

Overview

This release makes extensive changes to the Thread topology diagram, improving the usability of the product. It also improves the performance of the system, and the following describes the specific updates.

New features

  • Added the Border Router indication to the topology graph.
  • Added Keep Refresh switch to control the refresh of topology graph data.
  • Added display of more information about Thread devices, such as link quality, Thread version, IPv6 address, etc.
  • Added support for custom device names on the topology graph.

Improvements

  • Optimized the display of some pages, including topology page icons
  • Updated OpenThread version based on SiliconLabs GSDK v4.4.0.

Bug fixes

  • Fixed Bluetooth reporting empty data.
  • Fixed some known vulnerabilities.
4.1.4 2023-12-14
SHA256: 18c5a400ca8f5e27... SHA256: b51f1c63fcd0bca5... 🔗 share
Release notes

V4.1.4-0300

New Feature

  • Added NAT64 and mapping related functions.
  • Added the development board battery level indicator.
  • Added support to change the temperature unit of the development board.
  • Support development board firmware online switching FTD/MTD.
  • Show Name by default in Thread Topology Graph.

Optimization

  • Improved stability of the Thread Border Router.
  • Improved BLE stability.
  • Optimized the topology map display to show richer terminal status information.
  • Optimized the tips on the page.
  • Optimized the firmware upgrade function of the development board.

Bug fix

  • Fixed the problem of device reboot crash in certain cases.
  • Fix problems related to the BBR interface.
  • Fix the problem of packet loss in thread network in some cases.
  • Fix the problem of Joiner list import error in some cases.
  • Fix the problem of Thread App v1.1 failing to scan code.
  • Close WAN access ports 22/80/443 by default.
4.1.3 2023-03-06
SHA256: a7cc96c83aeae0a3... SHA256: 4cc3ba18dffa5a16... 🔗 share
4.7.0 2025-01-03
SHA256: 907ca99ae19be8d3... SHA256: 5cbeb944ae57ab78... SHA256: 232095af11be13b3... SHA256: bda1ea0f35fb72d0... 🔗 share
Release notes

v4.7.0-0501_beta1

Overview

This version mainly fixes a few known bugs.

Bug Fixes

Fixed the issue that when the main router uses global IPv6, devices on the local area network cannot access the Thread network.

About firmware listed under a “Factory” tab

GL.iNet occasionally ships routers with firmware versions that are not published to their download API or public download center. These factory-only builds typically have higher version numbers and newer packages than the latest publicly available Stable release.

Firmware images listed under the Factory tab were extracted from the eMMC partitions of routers running these factory-installed versions. The extraction is a read-only process that reconstructs a standard sysupgrade tar archive from the kernel and rootfs partitions. Binary cross-validation against the live router confirms accuracy of the extracted image.

Key differences from mirrored firmware:

These images are provided for users who need to restore a router to its exact factory-installed state (e.g., allow recovery from a firmware corruption or failed upgrade without forcing the user to downgrade/upgrade to a published version). See each entry's release notes for version-specific differences. Use at your own risk.

Official Business Partner
GL.iNet Business Partner