EdgeOS Firmware Changelog ==== Supported products * EdgePoint R6, model: EP-R6 * EdgePoint R8, model: EP-R8 * EdgeRouter X, model: ER-X * EdgeRouter X SFP, model: ER-X-SFP * EdgeRouter Lite, model: ERLite-3 * EdgeRouter PoE, model: ERPoe-5 * EdgeRouter, model: ER-8 * EdgeRouter PRO, model: ERPro-8 * EdgeRouter 4, model: ER-4 * EdgeRouter 6P, model: ER-6P * EdgeRouter 12, model: ER-12 * EdgeRouter 12P, model: ER-12P * EdgeRouter Infinity, model: ER-8-XG ==== 1.10.11 (e50, e100, e200, e300, e1000) Changelog / March 6, 2020 ==== Fixes: [PPPoE/L2TP/PPP] - Fix buffer overflow vulnerability in pppd daemon (CVE-2020-8597) [IPV6] - Allow packets with TTL=0 when "hwnat offloading" is enabled. This fixes DHCPv6 problems on ER-X/ER-X-SFP/EP-R6 models. [Offloading] - Fix bug when router randomly crashed after disabling offloading on ER-Lite, ER, ER-Pro, ER-Infinity, ER-4, ER-6P, ER-12. [WebGUI] - Regenerate WebGUI certificate if it does not meet new iOS 13 and MacOS 10.15 requirements. [IPSec] - Backport security fixes to strongswan v5.2.2 (CVE-2015-3991, CVE-2015-4171, CVE-2017-9022, CVE-2017-9023, CVE-2017-11185, CVE-2018-10811) [TechSupport] - Collect SLAB usage in support file [MDNS] - Fix bug when mdns service did not start with vti configured [Tcpdump] - Upgrade tcpdump v4.9.3 to fix RCE vulnerability (CVE-2018-14880) [SFP] - Fix bug when some SFP modules were mistakenly reporting TX error [SSH] - Limit permitted SSH MACs to those permitted by OpenSSH v7.4. Disabling some that are now considered weak and get flagged by vulnerability scanners as such.