OpenWRT

openwrt.org
OpenWRT

Plenty of scope for customization and a ton of supported addons. Stateful firewall, NAT, and dynamically-configured port forwarding protocols (UPnP, NAT-PMP + upnpd, etc), Load balancing, IP tunneling, IPv4 & IPv6 support.

Open Source

OpenWRT Privacy Policy

Privacy Policy Summary

  • There is a date of the last update of the terms
  • The service can delete your account without prior notice and without a reason

Score

D

Documents

Domains Covered by Policy

  • openwrt.org
  • forum.openwrt.org

About the Data

This data is kindly provided by tosdr.org. Read full report at: #1603

OpenWRT Source Code

Author

openwrt

Description

This repository is a mirror of https://git.openwrt.org/openwrt/openwrt.git It is for reference only and is not active for check-ins. We will continue to accept Pull Requests here. They will be merged via staging trees then into openwrt.git.

Homepage

License

NOASSERTION

Created

09 Nov 15

Last Updated

12 Jul 26

Latest version

v25.12.5

Primary Language

C

Size

301,398 KB

Stars

27,523

Forks

12,624

Watchers

27,523

Language Usage

Language Usage

Star History

Star History

Top Contributors

Recent Commits

  • Michael Pratt (04 Jul 26)

    tools: gnulib: rename macro file for cond module It was reported that cond.m4 in gnulib is a name clash with cond.m4 provided by Automake, where they are for completely different purposes instead of different versions of the same macros. A quick survey of all the macro files in the build directory reveals that this is the only case where the gnulib copy is signficantly smaller than the rest of the copies of the same macro name distributed in the rest of the build system, and the only one that name clashes with Automake. A previous fix added a prefix to all macros from gnulib, but the name must match how it is described in the respective modules files as a functional requirement to build certain tools for certain (older) hosts, so patch the problematic module instead of renaming all macros from gnulib. Ref: c820f097e0be ("tools: gnulib: install .m4 file with gl_ prefix") Ref: 78a8cfb57772 ("tools: gnulib: fix broken install of .m4 files") Reported-by: Christian Marangi <[email protected]> Signed-off-by: Michael Pratt <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24136 Signed-off-by: Robert Marko <[email protected]>

  • Michael Pratt (03 Jul 26)

    Revert "tools: gnulib: install .m4 file with gl_ prefix" A more proper fix follows this revert. This reverts commit c820f097e0bede3ec09c62ca9608d915da21e62d. Signed-off-by: Michael Pratt <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24136 Signed-off-by: Robert Marko <[email protected]>

  • Michael Pratt (03 Jul 26)

    Revert "tools: gnulib: fix broken install of .m4 files" A more proper fix follows these reverts. This reverts commit 78a8cfb57772138ff5b925b9d69928e5878931bf. Signed-off-by: Michael Pratt <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24136 Signed-off-by: Robert Marko <[email protected]>

  • Shiji Yang (27 May 25)

    lantiq: use gpiod API for PCIe GPIO reset This is the recommended way for the OF based platform. According to the original patch, set GPIO to low level to assert the reset, set GPIO to high level to deassert. Hence, adjust the dts GPIO polarity to active-low. Signed-off-by: Shiji Yang <[email protected]> Link: https://github.com/openwrt/openwrt/pull/18948 Signed-off-by: Jonas Jelonek <[email protected]>

  • Shiji Yang (07 Jul 26)

    tools/fakeroot: update to 2.1.3 Changelog: https://salsa.debian.org/clint/fakeroot/-/blob/debian/2.1.3-1/debian/changelog?ref_type=tags Signed-off-by: Shiji Yang <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24140 Signed-off-by: Jonas Jelonek <[email protected]>

  • Rosen Penev (11 Jul 26)

    gpio-button-hotplug: don't include of_irq.h Not used. Add the proper headers. Signed-off-by: Rosen Penev <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24177 Signed-off-by: Jonas Jelonek <[email protected]>

  • Rosen Penev (10 Jul 26)

    gpio-button-hotplug: remove pointless void cast void pointer casting like this is unnecessary. Signed-off-by: Rosen Penev <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24177 Signed-off-by: Jonas Jelonek <[email protected]>

  • Rosen Penev (10 Jul 26)

    treewide: remove weird double void casting This must be some older compiler and kernel warning. Signed-off-by: Rosen Penev <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24177 Signed-off-by: Jonas Jelonek <[email protected]>

  • Goetz Goerisch (07 Jul 26)

    ipq40xx: drop support for kernel 6.12 Drops support for kernel version 6.12 and corresponding patches Signed-off-by: Goetz Goerisch <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24128 Signed-off-by: Jonas Jelonek <[email protected]>

  • Goetz Goerisch (07 Jul 26)

    ipq40xx: switch to kernel 6.18 Switch default kernel verison to 6.18 build-tested: ipq40xx/chromium run-tested: ipq40xx/chromium Signed-off-by: Goetz Goerisch <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24128 Signed-off-by: Jonas Jelonek <[email protected]>

  • Robert Marko (06 Jun 26)

    Revert "generic: permit support of standalone PCS for external kernel module" This reverts commit 14beb3408d404e4929d3673047616ee5308a2f2f. It turned out not to be required. Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • Robert Marko (17 May 26)

    kernel: drop qca-nss-dp and qca-ssdk Now that all targets using NSS-DP and SSDK have been converted, we can finally drop these. Signed-off-by: Robert Marko <[email protected]>Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • George Moussalem (05 May 26)

    qualcommax: ipq50xx: convert to UNIPHY PCS and DWMAC stack Convert to UNIPHY PCS and DWMAC ethernet stack from qca-ssdk. Since we are not using SSDK anymore, we dont need to patch in the UNIPHY clock names anymore so drop the patch. Signed-off-by: George Moussalem <[email protected]> Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • Robert Marko (05 Jun 26)

    qualcommax: ipq50xx: support interface renaming Import the interface renaming script from filogic so we can use DTS label or openwrt,netdev-name to name interfaces from DTS on non DSA ports. Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • Robert Marko (20 Feb 26)

    qualcommax: ipq60xx/ipq807x: convert to PPE networking stack Convert IPQ60xx and IPQ807x devices from the old NSS dataplane to the new PPE stack. IPQ50xx is not yet supported. Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • John Crispin (18 Feb 26)

    qualcommax: replace NSS-DP DTSI with PPE DTSI Add DTSI files defining EDMA, PPE, and UNIPHY nodes for the new PPE driver bindings on IPQ5018, IPQ6018 and IPQ8074 platforms. IPQ5018 requires a patch for UNIPHY node as its cmn PLL node is upstream. These replace the existing NSS-DP ones. Signed-off-by: John Crispin <[email protected]> [IPQ5018] Signed-off-by: George Moussalem <[email protected]> [IPQ6018 and IPQ8074] Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • George Moussalem (19 May 26)

    qualcommax: ipq50xx: Enable RX and TX clocks for IPQ5018 GEPHY Clocks are disabled by default for IPQ5018 GEPHY, but they are required for the PHY to function properly. So let's enable the RX and TX clocks. Signed-off-by: George Moussalem <[email protected]> Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • Robert Marko (09 Mar 26)

    qualcommax: set USXGMII MAC autoneg bit on Aquantia PHY-s Now that we are not using SSDK anymore, we must set the USXGMII MAC autoneg bit manually, as otherwise MAC autonegotiation does not work. Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • George Moussalem (17 May 26)

    qualcommax: ipq50xx: add Qualcomm IPQ5018 DWMAC driver Add IPQ5018 DWMAC driver. IP version of this Synopsys DWMAC is 3.7. This Qualcomm IPQ5018 specific MAC implementation supports link speeds of 10HD/FD, 100HD/FD, 1,000HD/FD, and 2500FD and SGMII and 2500BASEX interface modes. The driver supports the MAC be attached directly to a PHY or via an optional PCS to a switch or PHY. Signed-off-by: George Moussalem <[email protected]> Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • John Crispin (11 Mar 26)

    qualcommax: add EDMA driver EDMA dataplane ethernet driver for Qualcomm IPQ platforms. Signed-off-by: John Crispin <[email protected]> [ rework Makefile for external repository, dependency ] Signed-off-by: Christian Marangi <[email protected]> [ rework for in-tree ] Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • John Crispin (11 Mar 26)

    qualcommax: add PPE driver PPE switch driver for Qualcomm IPQ platforms, depends on EDMA and UNIPHY PCS. Signed-off-by: John Crispin <[email protected]> [ rework Makefile for external repository, dependency ] Signed-off-by: Christian Marangi <[email protected]> [ bring PPE in-tree ] Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • John Crispin (11 Mar 26)

    qualcommax: add UNIPHY PCS driver PCS driver for UNIPHY SerDes blocks on Qualcomm IPQ platforms. Signed-off-by: John Crispin <[email protected]> [ rework Makefile for external repository, dependency ] Signed-off-by: Christian Marangi <[email protected]> [ make it in-tree under qualcommax ] Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • Christian Marangi (17 Mar 26)

    qualcommax: add pending patch to handle HW CLK recalc rate Add pending patch that introduce a new HW CLK OP to trigger recalculation of the rate. Signed-off-by: Christian Marangi <[email protected]> Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • John Crispin (18 Feb 26)

    qualcommax: add DSA out-of-band tagging protocol Add kernel patch for the DSA out-of-band tagging protocol used by the PPE switch driver, and enable CONFIG_NET_DSA_TAG_OOB. Signed-off-by: John Crispin <[email protected]> Link: https://github.com/openwrt/openwrt/pull/22381 Signed-off-by: Robert Marko <[email protected]>

  • rodriguezst (13 Jun 26)

    ramips: mt76x8: add support for Cudy LT500 Outdoor v1 Hardware: - SoC: MediaTek MT7628AN - Flash: 16 MiB SPI NOR - RAM: 128 MiB DDR2 - WLAN: 2.4 GHz (MT7628AN, 11n), 5 GHz (MediaTek MT7615E, 11ac) - Ethernet: 1x10/100 Mbps LAN - Buttons: 1 Reset button - LEDs: 8x Green - LTE: internal USB-connected modem Quectel EC200A - Serial Console: unpopulated header 115200 8n1 MAC addresses: +---------+-------------------+-----------+ | | MAC | Algorithm | +---------+-------------------+-----------+ | LAN | 80:af:ca:xx:xx:x0 | label | | WLAN 2g | 80:af:ca:xx:xx:x0 | label | | WLAN 5g | 80:af:ca:xx:xx:x2 | +2 | +---------+-------------------+-----------+ Migration to OpenWrt: - Download the RSA signed intermediate firmware: `openwrt-ramips-mt76x8-cudy_lt500-outdoor-v1-squashfs-flash.bin` - Connect computer to LAN and flash the intermediate firmware via OEM web interface - OpenWrt is now accessible via 192.168.1.1 Revert back to OEM firmware: - Press the reset button while powering on the device - Connect the LAN port to the PC - Open 192.168.1.1 in a browser and use the wizard to upload and flash OEM firmware image - When recovery process is done, OEM firmware is accessible via 192.168.10.1 again Signed-off-by: rodriguezst <[email protected]> Link: https://github.com/openwrt/openwrt/pull/23752 Signed-off-by: Hauke Mehrtens <[email protected]>

  • Shine (31 May 26)

    scripts: dhcp: option to override preferred Client ID per interface Using UUID-based client IDs for DHCPv4/DHCPv6 with no option of falling back to hardware IDs (ie. MAC-address or DUID-LL) resp. none at all (IPv4), is causing regressions in some setups. Introduce a new setting to override the preferred client ID to be used for DHCPv4/DHCPv6 on a per-interface basis: network.<ifname>.sendclientid='auto|global|hardware|none' - "auto" (default if empty or not present) uses any explicitly defined client ID, or falls back to the global DUID and finally to the DUID-LL resp. MAC address (ie. identical to before this commit). - "global" uses the global default DUID, if configured, for DHCPv4 and DHCPv6 requests, even if a client ID is explicitly specified for the i/f - "hardware" will not pass a client ID to udhcpc/odhcp6c, even if a global default DUID is configured or an explicit client ID specified, resulting in the i/f MAC address resp. type 3 DUID(-LL) to be used - "none" (IPv4 only) will not add an option tag 61 to DHCPv4 requests at all. Signed-off-by: Shine <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24107 Signed-off-by: Hauke Mehrtens <[email protected]>

  • Rosen Penev (10 Jul 26)

    gpio-button-hotplug: fix signed issue struct gpio_keys_button has an unsigned int for its irq field. A signed one is needed for fwnode_irq_get. Handle it before passing it to the button member. Fixes: 79b9a36959ea ("gpio-button-hotplug: use device and fwnode") Signed-off-by: Rosen Penev <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24174 Signed-off-by: Jonas Jelonek <[email protected]>

  • Mikhail Kshevetskiy (19 May 26)

    uboot-airoha: update to v2026.07 Changes: * removed upstreamed patches, * refresh patches, * add en7523/an7581/an7583 pinctrl support * add basic PCS support for an7583 * add an7583 specific mdio bus support Signed-off-by: Mikhail Kshevetskiy <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24165 Signed-off-by: Robert Marko <[email protected]>

  • Christian Marangi (10 Jul 26)

    airoha: enable NPU for Nokia device and fix ADC shunt-resistor Enable NPU and USB support for Nokia device and apply the correct value for the shunt-resistor for the i2c ADC chip to correctly read voltage. Signed-off-by: Christian Marangi <[email protected]>

  • Shiji Yang (06 Jul 26)

    uboot-tools: update to v2026.07 Update to the latest stable version. Also remove obsolete symbol PKG_CONFIG_SYSROOT_DIR[1]. [1] https://github.com/u-boot/u-boot/commit/8ef8dee4f3a2b2021decfefd853dbd2a1632b77f Signed-off-by: Shiji Yang <[email protected]> Link: https://github.com/openwrt/openwrt/pull/24123 Signed-off-by: Jonas Jelonek <[email protected]>

OpenWRT Security

5.2/10

Repo Security Summary

Updated 29 Jun 26

  • Packaging N/A
  • Maintained 10/10
  • Code-Review 9/10
  • Dangerous-Workflow 10/10
  • CII-Best-Practices 0/10
  • Token-Permissions 0/10
  • Security-Policy 0/10
  • License 9/10
  • Fuzzing 0/10
  • Branch-Protection N/A
  • Signed-Releases N/A
  • Binary-Artifacts 10/10
  • SAST 0/10
  • Pinned-Dependencies 0/10

Security Advisories (9)

  • medium Patched CVSS 4.9

    GHSA-jw5r-xhf5-2xcq ACL bypass and arbitrary root file read via cgi-io cgi-download

  • critical Unpatched CVSS 9.6

    GHSA-hhmc-92hw-535f odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI

  • medium Unpatched CVSS 6.5

    CVE-2026-55490 EAD Integer Underflow → Pre-Auth Denial of Service

  • low Patched

    CVE-2026-30874 procd: Command execution via PATH environment variable filter bypass

  • low Patched

    CVE-2026-30873 jsonpath: Memory leak when processing strings, labels, and regexp tokens

  • critical Patched

    CVE-2026-30872 mdnsd: Stack buffer overflow in IPv6 reverse DNS lookup

  • critical Patched

    CVE-2026-30871 mdnsd: Stack buffer overflow in DNS PTR query

  • high Patched CVSS 7.9

    CVE-2025-62526 ubusd: heap buffer overflow

  • high Patched CVSS 7.9

    CVE-2025-62525 ltq-ptm: local privilege escalation

OpenWRT Website

Website

Testing to determine if you are a bot!

Redirects

Does not redirect

Security Checks

1 security checks failed (64 passed)

  • Robots Noindex

Server Details

  • IP Address 64.226.122.113
  • Hostname wiki-03.infra.openwrt.org
  • Location Frankfurt am Main, Hessen, Germany, EU
  • ISP DigitalOcean LLC
  • ASN AS14061

Associated Countries

  • US US
  • DE DE

Safety Score

Website marked as moderately safe

90%

Blacklist Check

openwrt.org was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

OpenWRT Reviews

More Router Firmware

  • Easy and powerful user interface. Great access control, bandwidth monitoring and quality of service. IPTables is built-in for firewall, and there's great VPN support as well as additional plug-and-play and wake-on-lan features.

About the Data: OpenWRT

API

You can access OpenWRT's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/openwrt

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share OpenWRT

Help your friends compare Router Firmware, and pick privacy-respecting software and services.
Share OpenWRT and Awesome Privacy with your network!

View Router Firmware (2)