MX560 Firmware Release Notes
Version 12.01.07.151 (10/2022)
Major changes and improvements:
- Automatic migration of old mdex public.IP OpenVPN settings publicip.mdex.de
publicip20.mdex.de (security level 20).
- New added mdex public.IP OpenVPN profiles are using new OpenVPN settings for publicip20.mdex.de (security level 20).
- DDNS: A bug in the Dynamic DNS implementation has been fixed.
- System log: In case of "Save log in Flash memory" it is now written to a ring buffer to avoid memory overflows.
- Security: In the menu Network -> LAN -> Configuration -> Advanced Settings there is now a new option Enable IP Source Address Spoofing filter (enabled by default). This causes IP packets with false or spoofed sender IP addresses sent from the LAN to the router to be automatically discarded (according to RFC2827).
Updates & security improvements:
- Kernel: CVE-2020-25705 (Mitigation), CVE-2021-33909
- OpenSSL: CVE-2020-1971, CVE-2021-3712
- OpenVPN: CVE-2020-11810, CVE-2020-15078
- Busybox.wget: CVE-2018-1000500
- Dropbear: CVE-2020-36254
- Dnsmasq: CVE-2019-14834, CVE-2020-25681..CVE-2020-25687
- Luci: CVE-2019-12272, CVE-2020-28951
- Uhttpd: CVE-2019-19945
- Libubox: CVE-2020-7248
- Strongswan: CVE-2018-10811
- Hostapd: CVE-2019-16275
- Net-snmp: CVE-2020-15861, CVE-2020-15862
- Shellinabox: CVE-2018-16789
- Json-c: CVE-2020-12762
- Curl: CVE-2020-8169, CVE-2020-8231, CVE-2020-8285
Version 12.01.07.119 (07/2022)
Improved security of SMS implementation.
Version 12.01.07.115 (06/2021)
- I/O: fixed inverted input behaviuor and input rules execution on boot
- WebUI: fixed currently selected profile show in Input/Output rule edit page
Version 12.01.07.109 (03/2021)
- A problem with the transmission of IP data packets of exactly 512 bytes (and multiples) in the Telekom network has been fixed.
Version 12.01.07.105 (08/2020)
- PPP: fix Security Advisory 2020-02-21-1 - ppp buffer overflow vulnerability (CVE-2020-8597)
(Only relevant in rare cases, e.g. when establishing a PPPoE connection via an external DSL modem.)
Version 12.01.07.103 (09/2019)