Search changelog entries
| Component | Change |
|---|---|
| btest | improve stability; |
| console | improve stability; |
| fetch | improve stability of the TFTP client; |
| snmp | improve stability of SNMP; |
| ssh | refactor SSH internal processes and improved system stability; |
| system | improve stability; |
| system | updated certificate for Windows executable signing; |
| timezone | updated timezone information from "tzdata2026b" release; |
| Component | Change |
|---|---|
| app | add the networkRouterIP variable for container apps; |
| app | fix CHR apps getting stuck on "starting" on slower boards; |
| app | show an error when an app variable cannot be resolved; |
| app | update the environment variables of the docker-with-komodo app; |
| arm64 | improved general system stability; |
| bgp | add the always-compare-med setting; |
| bgp | fix BGP link-local nexthops unreachable over a VRF and a crash when disabling an unnumbered connection; |
| bgp | fix BGP unnumbered connections within a VRF; |
| bgp | include the VNI number in outgoing EVPN routes; |
| bgp | log failed BGP connection attempts; |
| bridge | add dynamic ARP inspection; |
| bridge | add IP source guard; |
| bridge | add mlag-lacp-fallback and mlag-init-delay settings for MLAG; |
| bridge | fix a false "already added as bridge port" error; |
| bridge | fix an MLAG peer getting stuck in the disabled state after config changes; |
| bridge | fix bridge ports not forwarding; |
| bridge | fix MLAG failing to establish after bridge config changes; |
| bridge | fix MLAG MAC handling when used with VRRP; |
| bridge | fix unexpected MAC aging in MLAG after a MAC move; |
| bridge | fix VRRP MAC behavior in MLAG setups; |
| bridge | improve stability; |
| bridge | make MVRP work with MLAG dual bonds; |
| bridge | rename the IGMP last-member-interval property to last-member-query-interval; |
| btest | improve stability; |
| bth | add resumable file uploads; |
| bth | allow file sharing over direct LAN connections; |
| bth | check the available disk space before a file upload; |
| bth | fix the file share getting stuck when disabling; |
| capsman | add hw-protection-threshold; |
| capsman | fix the last-ip value being shown backwards; |
| certificate | allow importing a cross-signed certificate without overwriting the existing one; |
| certificate | fix ACME certificate issuance for wildcard domains; |
| certificate | fix changing the built-in trust store setting (introduced in 7.22.2); |
| certificate | improve certificate import process; |
| certificate | refactor certificate internal processes; |
| cloud | improve stability of backup file downloads; |
| console | allow the array access operator to accept arrays of indices or keys; |
| console | expose globals in the API; |
| console | fix a memory leak in background scripts; |
| console | fix background ":execute as-string" jobs not terminating on interrupt; |
| console | fix comment wrapping in the monitor command; |
| console | fix inconsistent /ip/firewall/filter print with src-address-list and dst-address-list; |
| console | fix the where filter ignoring flags set to false; |
| console | improve export order; |
| console | improve stability; |
| console | prevent an out-of-memory condition when ":execute as-string" produces large output; |
| console | prevent duplicate entries in /port/remote-access; |
| container | add a Ctrl-] escape sequence to exit a stuck container shell; |
| container | fix container interface handling on CHR; |
| container | improve container image extraction; |
| container | require the container device-mode to enable swap; |
| crypto | fix a possible crash during IPsec processing on Qualcomm devices; |
| detnet | use a single random source port; |
| dhcpv4-server | add ipv6-only-preferred parameter to respect option 108; |
| dhcpv4-server | show DHCP option 82 parameters in ASCII in addition to hex; |
| dhcpv6-client | add option 39 with the client hostname; |
| dhcpv6-client | fix DHCPv6 client address handling after prefix-hint changes; |
| dhcpv6-client | remove a duplicate dhcp-options parameter; |
| dhcpv6-relay | use the packet's source MAC for option 79 if relay and client are on the same link layer; |
| dhcpv6-server | add option 39 (FQDN) support and add-dns-entries option; |
| disk | improve RAID5/6 throughput; |
| disk | improve stability of the SMB server; |
| dns | improve stability; |
| dot1x | improve stability; |
| dot1x | rename the reauth-timeout to reauth-period; |
| fix server certificate verification; | |
| show certificate related errors in the log; | |
| ethernet | add the arp-accept parameter for interfaces with MAC; |
| ethernet | fix a stability issue on RB1100AHx2 under heavy traffic; |
| ethernet | fix bogus fast-path Rx traffic reported on an unconnected ether8 port on RB5009; |
| ethernet | fix link flap and unexpected reboots on RB5009; |
| ethernet | fix PPPoE link flapping on Intel X710; |
| ethernet | fix PPPoE over VLAN not working on Mellanox ConnectX-4; |
| ethernet | fix SFP compatibility on E-series devices; |
| ethernet | improve stability on Alpine devices after a switch reset; |
| ethernet | improve stability on hAP be3 Media; |
| ethernet | improve stability on x86 routers with Mellanox NICs; |
| evpn | publish MAC-IP routes (RT-2) for neighbors; |
| fetch | improve stability of the TFTP client; |
| fetch | improve upload state reporting when using sftp; |
| fetch | never set a cookie jar for HTTP requests; |
| fetch | show a clearer error when keep-result and output are both used; |
| firewall | add NAT-related fields to CEF format logging; |
| hardware | show the device name and location in /system/resource/hardware menu; |
| igmp-proxy | improve stability when changing /routing/igmp-proxy parameters; |
| iot | add Bluetooth output power control; |
| iot | allow a custom radio plan even under a regional lock; |
| iot | enforce the fixed antenna gain on boards with an embedded antenna; |
| iot | fix round-trip-time timing issues in LoRaWAN Basic Station; |
| ip-service | fix services becoming unreachable after their VRF is disabled and re-enabled; |
| ipsec | add XFRM interface support; |
| ipsec | fix policy and SA handling after moving it to netlink; |
| ipsec | improve IKE handshake stability; |
| ipsec | improved service stability when processing an IKEv1 request; |
| ipv6 | add a neighbor discovery ping; |
| ipv6 | fix cases when address is lost after reboot if prefix was taken from pool; |
| ipv6 | fix the DNS timer in router advertisements; |
| ipv6 | ignore router advertisements received on interfaces not in the accepting list; |
| l3hw | fix IPv6 link-local traffic being routed incorrectly; |
| leds | add dark-mode support for L41; |
| leds | fix LEDs set to interface status staying off when the interface is active; |
| log | improve stability of logging; |
| lte | accept both y and yes for eSIM confirmation; |
| lte | add band display support for Huawei ME909s modems; |
| lte | add missing network error messages for MBIM modems; |
| lte | add support for supplementary downlink and uplink band only selection restriction; |
| lte | add the sms-protocol=qmi option for sending and reading SMS; |
| lte | use RA for IPv6 acquisition for FG621; |
| lte | fixed multi-APN for R11l-LTE7 and R11e-LTE6 modems; |
| lte | fix the RG650E-EU modem not bringing link up after a firmware update; |
| lte | fix traffic statistics in MBIM passthrough mode; |
| lte | remove leftover APN slave interfaces when the master LTE interface is removed; |
| lte | rename "firmware-update" to "firmware-upgrade" in the show-capabilities command output; |
| lte | fix the subscriber number not updating after switching SIM slots; |
| lte | fixed support for MC7710 Sierra modem; |
| lte | fixed IPv6 acquisition for R11e-LTE-US modem; |
| lte | improved link recovery for R11l-LTE7 modem; |
| lte | clear dhcp-server network in passthrough mode when the link goes down; |
| lte | improved system stability when using passthrough mode; |
| mac-telnet | improve stability of MAC Telnet sessions; |
| netinstall | fix a duplicate device entry on RB2011 with SFP; |
| netinstall | fix multiple active interfaces inheriting the first interface's settings; |
| netinstall | fix Netinstall failing to reinstall RB850Gx2 devices; |
| netinstall | fix Netinstaller's memory check failing downloads to disk; |
| ospf | fix DR/BDR traffic not being received with multiple instances; |
| ospf | improve stability when a neighbor is lost; |
| pim | add MLD support for PIM; |
| pim | fix duplicate PIM configuration parameters; |
| pim | fix PIM-SM issues with IPv6; |
| pim | fix wrong or missing PIM configuration by separating PIM and GMP per interface; |
| ping | add parameter checks for arp ping; |
| poe-out | fixed missing PoE-Out interface on hEX PoE lite, RB260GSP, OmniTIK 5 PoE, PowerBox; |
| port | accumulate incoming data in log file even without TCP clients connected; |
| port | add an FTDI latency_timer option for low-latency serial applications; |
| ppp | add port interface info to PPP outbound channel defaults; |
| ppp | fix a packet leak during dial-on-demand connection of a ppp-out interface; |
| ppp | fix BG77 modem port name and channel count; |
| ppp | fix the offline firmware-update notification for BG77/BG770 modems; |
| ppp | fix the SINR value reported for BG77 and BG770 modems; |
| ptp | add support for fixed master and slave port roles; |
| ptp | add transparent clock mode; |
| qos | fix PFC and lossless buffer issues (introduced in v7.23); |
| queue | fix a typo in the cake-overhead-scheme parameter value; |
| reverse-proxy | improve stability of the reverse proxy; |
| romon | improve stability of RoMON; |
| route | fix a nexthop mismatch; |
| routing | improve stability of routing protocol packet handling; |
| sniffer | improve packet time resolution; |
| snmp | add an OID and logging for blacklisted program access; |
| snmp | add CAPsMAN radio data to SNMP; |
| snmp | add dynamic SNMP engine ID assignment; |
| snmp | add interface table with mtu and l2mtu OIDs; |
| snmp | add IP pool OIDs; |
| snmp | add IPv6 address and interface name to the MNDP neighbour table; |
| snmp | add OID blacklisting; |
| snmp | add OIDs for Netwatch probes; |
| snmp | add OSPF MIB tables; |
| snmp | add SHA-2 authentication for SNMPv3; |
| snmp | add transmit drop counters; |
| snmp | add VRRP status OIDs for monitoring; |
| snmp | fix the reported capability flags in LLDP-MIB; |
| snmp | fix the snmp tools timing out when authentication is used; |
| snmp | improve stability of SNMP; |
| snmp | log a warning when the src-address family does not match the request; |
| snmp | remove an interface OID that should not be accessible; |
| socks | fix SOCKS proxy connection and address handling; |
| ssh | add host key verification for the SSH client; |
| ssh | limit server output to the client's window size; |
| ssh | refactor SSH internal processes and improved system stability; |
| ssh | show router host key fingerprint; |
| ssh | switch the default host key type to Ed25519; |
| ssl | enabled hardware accelerated GCM on Alpine CPUs; |
| ssl | improve logging; |
| switch | add packet and byte counters for ACL rules on Marvell Prestera switches; |
| switch | fix degraded slow-path throughput on CRS304 switch (introduced in v7.22); |
| system | fix memory handling and correctness issues in the core library; |
| system | fix the frequency units from Mhz to MHz; |
| system | improve stability; |
| system | reduce the fan control interval on multi-core boards; |
| system | remove the channel label from the RouterOS version; |
| system | warn about a missing wifi driver package on BE boards; |
| tftp | add VRF support; |
| tr069 | improve stability; |
| traffic-flow | improved system stability when disabling traffic flow on a busy system; |
| traffic-gen | improve stability; |
| upnp | improve stability; |
| usb | improve stability of RNDIS data handling; |
| user | fix removal of inactive REST API sessions (introduced in 7.21); |
| userman | improve stability when importing database files; |
| vlan | add a force-mac-address option for VLAN interfaces; |
| vrrp | improve stability; |
| webfig | add a generic table and union group support; |
| webfig | add column resizing to embedded tables; |
| webfig | hide the left menu only on QuickSet and Terminal pages; |
| webfig | improve stability; |
| webfig | update style; |
| webfig | update the login page Help link; |
| wifi | add a stream-port argument to configure the sniffer streaming server port; |
| wifi | add fast transition support for MLD devices; |
| wifi | add interworking, aaa and steering settings to the network configuration; |
| wifi | add more steering debug logs; |
| wifi | add network 'labels' parameter to WinBox and WebFig; |
| wifi | do not preserve branding package on cap when upgrading via capsman; |
| wifi | fix channel reselect interval/time operation for wifi-qcom-be and wifi-mediatek interfaces; |
| wifi | fix incorrect scan results for 320 MHz access points; |
| wifi | fix MLD link type change and SA query in station mode; |
| wifi | fix SAE authentication using a wrong cached PMK; |
| wifi | fix station statistics not updating after switching MLD links; |
| wifi | fix the interworking network type; |
| wifi | fix the wrong band shown in the registration table; |
| wifi | improve stability; |
| wifi | perform a channel switch instead of dropping clients on radar detection; |
| wifi | preserve dude package on cap when upgrading via capsman; |
| wifi | report channel in log messages; |
| wifi | report management frame protection (MFP) usage in registration-table; |
| wifi | show the EAP user identity in the registration table; |
| wifi | show the MLD links and SSID in MLO client log messages; |
| wifi-mediatek | improve MLO client reconnection; |
| wifi-qcom | fix disconnects during fast transition roaming; |
| wifi-qcom | fix station mode association failures; |
| wifi-qcom-ac | fix a regression in station MAC address handling; |
| wifi-qcom-ac | reduce package size; |
| wifi-qcom-be | add hw-protection-mode support; |
| wifi-qcom-be | add the distance setting for 802.11be devices; |
| wifi-qcom-be | fix the block ack request being declined after a channel switch; |
| wifi-qcom-be | fix Wi-Fi intermittently unavailable after reboot; |
| wifi-qcom-be | improve throughput in dense client environments; |
| wifi-qcom-be | upgrade driver and firmware; |
| winbox | add a filtered LLDP tab to neighbor discovery; |
| winbox | add a Security tab and reorganize bridge and port dialogs; |
| winbox | add a wifi radio regulatory info (reg-info) view; |
| winbox | add device-mode configuration; |
| winbox | add ISIS support; |
| winbox | add progress bar support to the GUI; |
| winbox | add RSRP and RSRQ signal graphs to the PPP info view; |
| winbox | add the client MTU option for WireGuard peers; |
| winbox | add the container save option; |
| winbox | add wifi Spectral Scan support; |
| winbox | allow power-cycling multiple interfaces at once; |
| winbox | allow tuple fields with more than two values and multiple separators; |
| winbox | fix SFP optical power values of 0.0 dBm not being shown; |
| winbox | fix the "addresses" spelling in read-only fields; |
| winbox | fix the EC/IO signal quality graph; |
| winbox | fix the ISIS neighbor level type being empty for "l2"; |
| winbox | fix the Memory Limit field of fq_codel to use bytes; |
| winbox | fix the Min Prefix field in the routing rule dialog; |
| winbox | fix the MPLS TE tunnel path hops field; |
| winbox | fix the range field displayed in route filters; |
| winbox | fix the Skins menu for user groups opening a non-existent window; |
| winbox | fix the system note display on startup; |
| winbox | fix the wifi Authentication Types and Encryption fields; |
| winbox | improve stability of WinBox protocol handling; |
| winbox | improve status reporting under Tools/Email menu; |
| winbox | make the Power Cycle button act only on the selected interface; |
| winbox | open the Format Drive panel only for supported disks; |
| winbox | remove the redundant empty status field from the License window; |
| winbox | rename "send" to "transmit" in the Bandwidth Test window; |
| winbox | rework the switch QoS statistics table; |
| winbox | show WireGuard peer information; |
| wireguard | add the client-mtu parameter; |
| wireguard | allow referencing a peer by its name; |
| wireguard | allow unsetting the client-listen-port; |
| wireguard | improve error message reporting when adding a new peer; |
| wireguard | keep peer rx/tx counters when the peer is disabled and enabled; |
| wireguard | use the MTU value when importing a configuration; |
| wireguard | warn when an allowed-address overlaps another peer; |
| www | add the remote client IP and domain to HTTPS log messages; |
| www | fix a memory leak when parsing authentication headers; |
| www | improve stability; |
| www | improve URI parsing; |
| Component | Change |
|---|---|
| app | fix entrypoint and cmd for opencloud-extended-collabora app; |
| bridge | fix missing host "E" flag for CRS8xx series switches; |
| bridge | fix MLAG for CRS8xx series switches; |
| bridge | fix stability issue when using VRRP on bridge; |
| bridge | improve MLAG host aging and deletion logic; |
| console | fix "find" command argument lookup issue (introduced in v7.24); |
| container | improve host isolation when container is set to "privileged=yes"; |
| l3hw | fix stability issue on IPv6 offload enable; |
| l3hw | fix VRF offload on bond interface remove; |
| leds | fix "interface-status" trigger; |
| snmp | properly validate password length when applying configuration; |
| ssh | refactor SSH service internal processes; |
| switch | fix possible Rx traffic stall on CPU for devices with Marvell Prestera switch chip; |
| switch | fix stability issue during L2 loop for 98DX224S, 98DX226S, 98DX2528, and 98DX3236 switch chips; |
| switch | fix stability issue on RB3011 (introduced in v7.22); |
| system | improve handling of invalid SSL/TLS requests; |
| wifi | fix stability issue for hAP be lite; |
| wireguard | fix peer disable/enable state handling, which could leave the tunnel non-functional (introduced in v7.24); |
| wireguard | fix private key handling, including empty private keys; |
| www | improve service responsiveness when receiving malformed packets; |
| Component | Change |
|---|---|
| adlist | improved service stability when adjusting adlist configuration; |
| app | added "HF_TOKEN" env to openwebui; |
| app | added "network-outgoing-access" parameter which does not allow app to make outgoing connections; |
| app | added hermes-agent, inventree, opencloud, opencloud-extended apps; |
| app | added PAPERLESS_SECRET_KEY env to paperless-nginx; |
| app | allow "reset" even if disk not configured; |
| app | allow HTTP for Gitea when "check-certificate=no"; |
| app | allow setting "working_dir" in app YAML; |
| app | changed pmacct-netflow YAML; |
| app | disable UI in Hermes, access through /container/shell; |
| app | fixed apps not updating firewall redirects when changed in YAML; |
| app | fixed apps sometimes getting stuck on "waiting for layer"; |
| app | make secrets sensitive to avoid polluting configuration export; |
| app | removed healthcheck from opencloud-extended-collabora; |
| app | reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stop; |
| app | show CHR's address instead of the container's; |
| app | use randomly generated secrets in new apps; |
| bgp | fixed EVPN label corruption and corrected EVPN type-5 output; |
| bgp | improved stability when receiving malformed packets; |
| bgp | removed "save-to" from "resend" command; |
| bgp-vpn | fixed blackhole route export; |
| bridge | added "querier-uses-bridge-address" setting to use bridge source IP address for IGMP querier; |
| bridge | added DHCPv4 snooping IP binding table; |
| bridge | added scheduling point during VLAN processing to prevent soft lockups when flushing FDB over large VLAN ranges; |
| bridge | fixed forwarding through peer-port after disabling MLAG; |
| bridge | fixed local static host entries; |
| bridge | fixed MLAG MAC address handling issues related to aging, flushing and moving; |
| bridge | fixed stability issue when using DHCPv4 snooping; |
| bridge | fixed stuck MLAG session when using mismatched L2MTU (introduced in v7.23); |
| bridge | improved bridge and port STP "priority" setting (warn when a non-compliant value is used and allow selecting a value from a list); |
| bridge | improved STP, BPDU and topology change handling with MLAG, ensure dual-connected port STP state is in sync with MLAG peer; |
| btest | added VRF support for bandwidth-test and speed-test; |
| certificate | added "acme-renew" command; |
| certificate | general improvements in certificate handling; |
| certificate | use AES encryption when exporting certificates in PKCS#12 format; |
| console | added "days" to scheduler; |
| console | added "in" and "has" operators for array types; |
| console | added "order-by" parameter to "print" command, allowing sorting by up to three arguments in ascending or descending order; |
| console | added comparison operators for array type; |
| console | added log tracing when scripts fail to start due to permissions; |
| console | do not terminate self-removing scripts; |
| console | fixed "print follow on-event" script runner command not showing all argument values in some cases; |
| console | fixed argument mappings in "do" block for monitor commands; |
| console | fixed proplist order in monitor commands; |
| console | fixed script import/export with empty "policy" setting; |
| console | fixed stability issue in full-screen editor; |
| console | fixed UTF-8 comparisons on some architectures; |
| console | improved "print detail" mode; |
| console | improved script handling and error logging when running scripts from external sources (e.g. DHCP, SNMP, Netwatch, etc.); |
| console | make "mac-auth-password" sensitive in "/ip/hotspot/profile"; |
| console | make "password" sensitive in "/system/package/local-update/mirror"; |
| console | produce runtime errors for bad command parameters; |
| console | prompt about and offer to stop already existing serial terminal session when opening new one; |
| console | renamed "address" to "available-from" in "/ip/service" (backwards compatible via deprecation); |
| console | renamed "reauth-timeout" to "reauth-period" in "/interface/dot1x/server" (backwards compatible via deprecation); |
| console | restrict editing comments in WiFi registration table; |
| container | added "save" command to allow saving container images; |
| container | added "swap-current" usage; |
| container | added "swap-max" global and per-container limit; |
| container | added ability to run containers in privileged mode; |
| container | added initial support for RKE2; |
| container | do not allow starting with empty default DNS list and no DNS override; |
| container | do not print environment variables in log on container startup; |
| container | fixed "start-on-boot" not retrying on certain startup errors; |
| container | fixed container "devices" override to appear under "/dev"; |
| container | improved layer size calculation to avoid potential loops; |
| container | improved support for containers; |
| container | reduced writes to flash when running health check; |
| container | use env "TERM=xterm" if no TERM variable provided when running shell; |
| crypto | fixed hardware accelerator for GCM cipher in TLS connection on Alpine CPUs; |
| defconf | set "configuration.dtim-period=3" for WiFi; |
| defconf | use "add-dns-entries=yes" on devices with DHCP server; |
| dhcp | fixed processing of DHCP options that are longer than 255 bytes; |
| dhcpv4-relay | fixed stability issue when creating duplicate relays; |
| dhcpv4-server | do not reset "class-id" parameter when lease loses "bound" status; |
| dhcpv4-server | set "ciaddr" in forcerenew messages so a relay, if used, can unicast such messages; |
| dhcpv6-relay | fixed non-working relay when adding from WinBox; |
| dhcpv6-server | fixed invalid flag; |
| discovery | added "address6" column to default "/ip/neighbor" print view; |
| discovery | added "discovery" logging topic; |
| discovery | added "dying-gasp" feature for LLDP, MNDP, CDP that sends packet with "TTL=0" before graceful reboot/shutdown/upgrade; |
| discovery | clear neighbor entry when receiving "dying-gasp" packet; |
| discovery | improved service stability when sending discovery packets on interfaces that have hundreds of IP addresses; |
| disk | added "last-seen" property that displays disk model and serial when removed; |
| disk | added "raid-scrub-cancel" command; |
| disk | added error message when disk state transitions from good to bad; |
| disk | do not consider USB drives as self-encryption capable; |
| disk | fixed "smart-info" not showing information on certain storage devices; |
| disk | limited maximum swap size to be no more than 10x of device RAM; |
| disk | resolved issue where storage device might change information upon reboot; |
| ethernet | disable EEE on hAP be3 Media; |
| ethernet | fixed stability issue for Chateau PRO ax devices; |
| ethernet | fixed stability issue for devices with Alpine CPU; |
| ethernet | removed "1G-baseT-half" link mode on RTL8367 switch; |
| fetch | added "ip-type" parameter; |
| fetch | added option to force HTTP/2 only (only for ARM64 and x86/CHR devices); |
| fetch | fixed false "bad request" response when trying to fetch URL with IPv6 address in it; |
| fetch | hint file list for "src-path" and "dst-path" parameters; |
| hardware | renamed "max-power" to "manufacturer-reported-max-power"; |
| iot | added LoRa keep alive logic for UDP protocol; |
| iot | added missing LoRa US radio plans; |
| iot | added Wiliot USB dongle support; |
| iot | allow maximum Modbus "timeout" property to be 10 seconds; |
| iot | monitor LoRa worker state (watchdog); |
| iot | pass Wiliot certification; |
| ip-service | remove reverse-proxy for SMIPS; |
| ip-service | show service name for "l2tp"; |
| ipsec | fixed expired SA handling to prevent “no such item” errors during listing; |
| ipsec,ike1 | dropped base mode exchange; |
| ipsec,ike1 | fixed negotiated PFS validation; |
| ipsec,ike1 | improved SA, transform, fragment parsing and malformed packet validation; |
| ipsec,ike2 | fixed ppk child key generation during rekey; |
| ipsec,ike2 | improved KE generation validation during initial setup and child SA creation; |
| ipsec,ike2 | improved PPK handling by always using it when authorized, including additional Child SAs, and moved PPK processing to the Child SA task; |
| ipsec,ike2 | use first child KE selection only during IKE_AUTH exchange; |
| ipsec,qkd | moved QKD to "/system/keymat-provider" menu and made it a generic key material provider; |
| ipv6 | added "status" column to default "/ipv6/neighbor" print view; |
| ipv6,ra | changed default "router-advertisement-route-distance" to 1; |
| ipv6,ra | correctly process RAs advertising previously expired prefix; |
| ipv6,ra | fixed prefix invalidation; |
| ipv6,ra | use lowest value between IPv6/Pool and IPv6/ND/Prefix/Default as dynamic prefix lifetime; |
| isis | fixed ECMP route removal; |
| l2tp | allow fragmentation of large IPv6 packets; |
| l3hw | added HW offloaded support for VLAN interfaces created directly on Ethernet for CRS8xx series switches; |
| l3hw | added HW offloaded VRF support on 98DX8208, 98DX8216, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255, 98CX8410 switches; |
| l3hw | added VRF assignment via switch ACL rules for devices with Marvell Prestera switch chip; |
| l3hw | allow VLAN tagged traffic inside VXLAN tunnel; |
| l3hw | fixed VRF-related issues for CRS8xx series switches; |
| l3hw | fixed VTEP offload on IPv4 /32 route changes; |
| leds | added dark mode support for L009, hAP ax2, hAP ax3, hEX refresh, hEX S (2025), hAP ax S and Chateau ax devices; |
| leds | fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23); |
| leds | improved interface stats activity for devices with Marvell Prestera switch chip; |
| lte | added force-confirmation parameter for eSIM provision command; |
| lte | cap IPv6 prefix lifetime for ipv6-interface; |
| lte | do not add extra /128 IPv6 address for ipv6-interface; |
| lte | do not query 5G neighbor cell info until RG650E-EU FW fixed; |
| lte | enabled AT registration unsolicited event reporting for EG25-G and EC25-EU boards; |
| lte | fixed cases where R11l-LTE7 modem would not display correct cell info after handover; |
| lte | fixed EC/IO scale in CLI and GUI; |
| lte | fixed EC25-EU, EG25-G traffic to 67 UDP; |
| lte | fixed IPv6 RA handling for multiapn non-primary interface; |
| lte | fixed third-party modems ICCID decoding for eSIM; |
| lte | improved Cinterion PLS8-E roaming; |
| lte | improved deregistration handling for AT modems; |
| lte | improved system stability when no APN specified; |
| lte | improved USB mode handling for BG770A-GL; |
| lte | limit IPv6 prefix lifetime only when lifetime is advertised as infinity; |
| lte | make modem MAC persistent for R11e-LTE6 and R11l-LTE7 modems; |
| lte | remove site local DNS for ipv6-interface; |
| lte | removed extra restart after firmware upgrade for EC200A-EU modem; |
| lte | report short cell ID in 3G network mode also for AT modems; |
| lte | restrict incoming calls for FG621-EU; |
| lte | show "+CME ERROR: 10" as "SIM not present"; |
| lte | show "data-class" in LTE monitor instead of "access-technology" also for 5G AT modems; |
| lte | show "primary-band" instead of "earfcn" in LTE monitor also for modems without CA support; |
| lte | show RSCP and EC/IO parameter in 3G network mode for R11e-LTE6, R11l-LTE7 and FG621-EA modems; |
| mesh | fixed missing FDB entries from wireless ports; |
| mpls | added ICMP time exceeded handler for IPv6; |
| mpls | make FastPath work with expl-null; |
| netinstall | added Netinstall package; |
| netinstall | improved architecture detection; |
| netinstall-cli | added "help" parameter; |
| netinstall-cli | added "reboot" and "shutdown" flags to control reboot after installation; |
| netwatch | fixed an issue with DNS probe "timeout" parameter; |
| netwatch | fixed HTTP GET probe over IPv6; |
| netwatch | fixed inaccurate "rtt-stdev" value; |
| netwatch | fixed issue where ICMP probes did not accept TTL exceeded packets when "accept-icmp-time-exceeded" was enabled; |
| netwatch | increased maximum packet size to 65535; |
| ospf | fixed stability issue during interface flaps; |
| ospf | force passive for VRF interface; |
| pimsm | make "hash-mask-length" parameter naming consistent and fixed typos; |
| poe-in | added PoE-in monitoring and LLDP-based PoE negotiation support for newer devices (e.g. CRS504, CRS510, hEX S 2025, hAP be3 Media); |
| poe-out | firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces); |
| poe-out | firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces); |
| ppp | added "MT-Address-List" to IPv6 address list when received from RADIUS and using DHCP for IPv6 configuration; |
| ppp | added iccid field to ppp info command for BG77 and BG770 modems; |
| ppp | always show current FW version when running firmware-upgrade; |
| ppp | disable/enable modem radio state depending on ppp interface state; |
| ppp | fixed cases where BG77 or BG770 firmware upgrade was not available; |
| ppp | fixed ppp-out stability issue; |
| ppp | get IPv6 configuration via RA for modems using PPP emulation mode; |
| ppp | improved "info" command for BG77 and BG770 modems; |
| ppp | improved OVPN underlying SSL connection management; |
| ppp | only show pin in export with "show-sensitive" flag; |
| ppp | report actual network data usage statistics instead of "0" for all IPv6 RADIUS accounting parameters on accounting "Stop" packet; |
| ppp | toggle radio state on interface disable/enable; |
| queue | fixed "undo" command for simple queues; |
| reverse-proxy | improved stability; |
| rip | do not export authentication keys by default; |
| route | allow to add route with link-local destination address; |
| route | fixed memory leak when flapping addresses or interfaces with routing protocols running; |
| route | fixed potential race condition; |
| route | respect the "interface" property when pinging IPv6 addresses over ECMP; |
| sfp | fixed linking for hAP ax S and hEX S (2025) with "1G-baseX" link-mode; |
| sfp | removed unsupported "2.5G-baseX" speed on CRS312-4C+8XG and CRS326-4C+20G+2Q+; |
| sftp | fixed branding package upload; |
| sms | added some GSM7 symbols to SMS tool; |
| snmp | added hotspot active-user-count and host-count OIDs to MIKROTIK-MIB; |
| snmp | added missing SFP OIDs to MIKROTIK-MIB; |
| snmp | added WiFi current channel "mtxrWifiInterfacesCurrentChannel" OID to MIKROTIK-MIB; |
| ssh | added mlkem768x25519-sha256 key exchange support; |
| ssh | do not attempt automatic empty password login when RADIUS is used; |
| ssh | fixed SSH tunnel with IPv6 link-local address on non-ethernet interfaces; |
| ssh | make SSH packet validation more strict; |
| supout | added interface monitor-traffic; |
| supout | added LTE eSIM section; |
| switch | fixed IEEE reserved MAC handling for CRS1xx, CRS2xx switches; |
| system | improved stability; |
| system | renamed "factory-software" to "minimum-version" and "factory-firmware" to "minimum-firmware"; |
| system | restrict RouterOS processes using swap; |
| system | show who is using "/system serial-terminal"; |
| traffic-generator | fixed injecting pcap/pcapng files on MIPSBE architecture; |
| tunnel | fixed stability issue caused by a misconfigured routing loop under bridge (introduced in v7.22); |
| upgrade | removed sensitive policy for "apply-changes" command; |
| usb | allow overriding the power-reset duration; |
| usb | fixed USB Ethernet interface default-name; |
| vpls | added transmit loop detection; |
| vrrp | added "v3-checksum-as-v2" setting; |
| vrrp | fixed stability issue when "sync-connection-tracking" is enabled; |
| vxlan | fixed missing L2MTU property when VRF is specified; |
| vxlan | ignore disabled interfaces when checking for configuration conflicts; |
| webfig | fixed issue with increasing keep-alive traffic; |
| webfig | improved underlying encryption and stability processing; |
| webfig | improvements to graphs; |
| wifi | added "Preamble Puncturing" under "WiFi/Channel" menu; |
| wifi | added dash when CAPsMAN generates interface name and prefix ends with digit; |
| wifi | improved roaming/steering behavior for WiFi 7 MLO; |
| wifi | improved stability; |
| wifi | improved station-bridge mode; |
| wifi | updated radio regulatory information; |
| wifi | upgraded wifi-qcom driver; |
| wifi-mediatek | fixed broken interfaces on startup; |
| wifi-mediatek | fixed some channel definitions for certain countries; |
| wifi-mediatek | improved channel switching; |
| wifi-mediatek | improved stability during MLO channel switching; |
| winbox | added "Network" configuration menu for WiFi; |
| winbox | added "Preferred Architecture" setting for L009; |
| winbox | added "SIM PIN" under "Tools/SMS"; |
| winbox | fixed "Connection Bytes" field under "IP/Firewall" menu; |
| winbox | fixed "EC/IO" scaling for LTE interface; |
| winbox | fixed "Use Ipsec" and "Ipsec Secret" under "Interfaces/L2TP Ether" menu; |
| winbox | fixed empty value in "Immediate Gateway" under "IP/Routes" menu; |
| winbox | fixed sort for "Address List" under "IPv6/Firewall" menu; |
| winbox | make LoRa "Auth key" and MQTT "Password" sensitive; |
| winbox | move "EAP" under "Security" tab for WiFi; |
| winbox | show "Any. Port" column by default under "IP/Firewall" menu; |
| winbox | show preferred and valid lifetime of IPv6 address also on static IPs; |
| winbox | show priority bits in "VLAN ID" field under "Tools/Packet Sniffer" menu; |
| wireguard | added support for domain names in client-dns; |
| wireguard | added warning when allowed-address overlaps with another peer on the same interface; |
| wireguard | fixed peer recreation on interface change; |
| wireguard | fixed peer Tx/Rx counters; |
| wireguard | fixed wg-export comments output and case when endpoint is not set; |
| wireguard | fixed whitespace handling in AllowedIPs during wg-import; |
| wireguard | generate port number when specified as zero; |
| wireguard | improved wg-export to print endpoint domain name; |
| wireguard | improved wg-import to quietly ignore wg-quick specific keys; |
| wireguard | reconfigure peer only when meaningful changes are detected; |
| wireguard | reinitialize socket on VRF change; |
| x86 | fixed IRQ displaying per CPU on Intel 700 series NIC; |
| Component | Change |
|---|---|
| app | added PAPERLESS_SECRET_KEY env to paperless-nginx; |
| app | disable UI in Hermes, access through /container/shell; |
| app | reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stop; |
| ethernet | disable EEE on hAP be3 Media; |
| ip | improved stability for reverse-proxy (additional fixes); |
| ipsec | fixed expired SA handling to prevent “no such item” errors during listing; |
| ipsec,ike1 | dropped base mode exchange; |
| ipsec,ike1 | improved SA, transform, fragment parsing and malformed packet validation; |
| ipsec,ike2 | fixed ppk child key generation during rekey; |
| ipsec,ike2 | use first child KE selection only during IKE_AUTH exchange; |
| leds | fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23); |
| poe-out | fixed possible PoE-out configuration loss on certain devices (introduced in v7.24beta1); |
| switch | fixed default L2MTU drift for devices with QCA8337, Atheros8327 switch (introduced in v7.24beta2); |
| system | improved stability; |
| usb | allow overriding the power-reset duration; |
| wifi | updated radio regulatory information (additional fixes); |
| wireguard | fixed peer Tx/Rx counters; |
| wireguard | generate port number when specified as zero; |
| wireguard | reinitialize socket on VRF change; |