#openwrt

27 posts · Last used 9d

Back to Timeline
Michael Koerfer @OT_MacDonald@infosec.exchange · Aug 05, 2026

Powerful Hardware Turned into E-Waste

What you're looking at is another unfortunate example of perfectly capable hardware becoming electronic waste long before its technical lifespan is over.

This is the AirTies Air 4960, an AX5400 Wi-Fi 6 mesh extender/access point featuring impressive hardware:

  • Broadcom BCM6752 triple-core ARM Cortex-A7 SoC (up to 1.5 GHz)
  • Broadcom BCM43684 4x4 Wi-Fi 6 radio with 160 MHz channel support
  • Dual-band Wi-Fi 6 (802.11ax)
  • Two Gigabit Ethernet ports
  • Around 4.5 W power consumption

From a technical perspective, this device is still more than capable of delivering excellent performance in many home and enterprise networking scenarios.

  • The Real Issue

The hardware isn't obsolete, the software ecosystem is intentionally locked down.

Many devices like this are heavily restricted by manufacturers or Internet Service Providers (ISPs), preventing owners from repurposing them once official support ends or the service contract expires.

Meanwhile, open-source firmware projects such as OpenWrt, DD-WRT and Tomato have demonstrated for years that networking hardware can remain secure, functional, and useful far beyond its commercial lifecycle.

Unfortunately, locked bootloaders, proprietary firmware, missing documentation, and closed-source drivers often make that impossible.

Sustainability Is Also About Software Freedom

We regularly discuss sustainability, circular economy, and reducing electronic waste.

Yet perfectly functional networking equipment ends up in recycling bins, not because the hardware has failed, but because users are prevented from installing alternative software.

  • The hardware already exists.
  • The raw materials have already been mined.
  • The manufacturing energy has already been spent.

In many cases, all that's missing is the freedom to install an alternative operating system.

  • A Better Approach

I would like to see manufacturers embrace a more open ecosystem by providing:

  • Unlockable bootloaders
  • Public hardware documentation
  • Support or at least tolerance for open-source firmware
  • Longer software support lifecycles

This would benefit users, enterprises, developers, the open-source community, and ultimately the environment.

Not every retired device is obsolete, many are simply made obsolete through artificial restrictions.

#OpenSource #OpenWrt #DDWRT #WiFi6 #Networking #Sustainability #CircularEconomy #RightToRepair #EmbeddedLinux #Broadcom #eWaste #Technology

20
1
21
9Lukas5 🚂 🐧 @9Lukas5@mastodontech.de · Aug 05, 2026
Oh gosh darn it 😐 Wanted to change the admin password. Opened the webui (LuCI), changed the system admin password, logged out...can't log in anymore. Neither with the old nor the new one I can get in anymore 🙈 #OpenWRT #Router #Password #LuCI #Security #Credentials #Password #PasswordFail
0
0
0
uvok Grumpyspots @uvok@woof.tech · Aug 04, 2026
Replying to @uvok@woof.tech
I restarted #babeld on my #openwrt router. This... fixed the problem?
0
1
0
Alper Çelik :cpp: :nix: @Alper_Celik@infosec.exchange · Aug 03, 2026
i want to try doing #OpenWRT #extroot kind of thing but with #nfs . since my #router doesn't have usb slot and its flash is 8mb. I am thinking about putting NFS mounting after core services are up and network is somewhat operational to not have cascading network failures stemming from vps being down or chiken and egg problem with local nfs share not being able to connect to it. like i currently want it for running #tailscale subnet router directly on router instead of running it on another device with static route on the router. also i kinda want to try running actual #mulvadvpn cli client instead of wireguard profies to be able to use #DAITA and anti censorship features. tho i am not sure how mulvads #nftables rules would interact with openwrt firewall which uses nftables under the hood.
0
0
0
Owl Eyes Hoo @d1@autistics.life · Aug 03, 2026
Replying to @jbrownesq@mastodon.social
@jbrownesq@mastodon.social I have 2 #OpenWRT routers myself 👍
1
1
0
Flüpke @fluepke@chaos.social · Aug 01, 2026
Boosted by Trending Bot @trending@homestead.social
Public S3 Bucket with schematics, secure boot keys, arm trusted firmware signing keys for commercially available ONTs and #Realtek xPON SDK, that usually requires signing nasty NDAs: mk-wangtong.s3.amazonaws.com The SDK contains kernel drivers for Realtek xgspon / gpon chips. From PLOAM to OMCI – all there. Please share with #openwrt devs and anyone you know of, who might be messing around with #GPON and #xgspon. :BoostOK: I want to see some open-source & open-hardware ONTs 😈
105
5
101
Cloud 🤖 @cloud@infosec.exchange · Jul 28, 2026
🤖 CVE-2026-53921 (CVSS 9.8): Critical unauthenticated DHCPv6 stack overflow in OpenWrt odhcpd allows RCE as root. OpenWrt 24.10.8 released with fix. No auth required — affects default-enabled DHCPv6 service. 🔗 https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html #CVE #CyberSec #OpenWrt #RCE
0
0
0
Jörg 🇩🇪🇬🇧🇪🇺 @AlienJay@burningboard.net · Jul 26, 2026
Ich überlege immer noch, wie ich das hier mit meiner Technik am Besten lösen kann. Was soll hier in Zukunft laufen? Smart Home mit Home Assistant Open WRT ADSB Empfänger Reverse Proxy (Nginx) Snowflake Proxy Pi Hole (2x) Aktuell gehobene Tendenz dahin mit einem Adapter von GeekPi 3 Raspberry in mein 19 Zoll Rack einzubauen. Einer für Open WRT, einer für Home Assistant und einer für den Rest. Dann muss ich sehen, wo der zweite Pi Hole hin wandert. Ggf. auch nur ein Pi Hole und einmal Open WRT benutzen. Der kann das auch mit den selben Filterlisten. Ich würde dann im Rack versuchen ein ordentliches 60W Netzteil einzubauen, das alle Raspberries versorgt. Einen kleinen PC zu verbauen wäre wahrscheinlich zu teuer. Da der auch schon ein bisschen was leisten müsste wahrscheinlich auch vom Energieverbrauch mehr. Dann alles vitualisieren. Router wäre dann auch da drauf. Wohl keine gute Idee. Ich weiß es nicht. Mal sehen #Netzwerk #openwrt #raspberrypi #homeassistant #smarthome #adsb #pihole
0
3
0
Limping @limping@mastodon.ml · Jan 28, 2026
Replying to on mastodon.ml
Прогрессивная штука #OpenWRT, без сомнения. Но одно расстраивает. Отключение #IPv6 - даже в 2026 году там пользователи себе прописывают прямо в uci-defaults Такое ретроградство, конечно, не от хорошей жизни. Я раньше тоже отключал, но теперь... NTC.party заставляет задуматься, и вообще. Вижу, как много ресурсов на кинетике пашут именно через IPv6.
3
1
2
Anton Arapov @mold@infosec.exchange · Jul 20, 2026
The result of a couple of weeks deep in the world of optical networking: my O2/CETIN fiber now terminates in an SFP+ stick, not the ISP's ONT box. Turns out XGS-PON stick modules run OpenWrt inside — and I simply couldn't walk past that. I've loved OpenWrt since forever. Can't say the same about the ISP's box... who knows what's inside. 🙂 Full write-up — diagnosis, the missing-bridge-port trap, the fix: https://gist.github.com/arapov/a2019f5dac903864f36102184ff2755a #OpenWrt #XGSPON #FTTH #GPON #homelab
0
0
0
uvok Grumpyspots @uvok@woof.tech · Jul 14, 2026
Yay! First time I built myself an #OpenWRT package! It was a build of luci-app-babeld from master, since the release branch still contained an ugly bug. Now I see the routes again! :D
0
1
0
Michael Koerfer @OT_MacDonald@infosec.exchange · Jul 12, 2026
U-Boot, a widely used open-source bootloader, is reported to contain six security vulnerabilities that allow attackers to run malicious code or crash devices during the boot process. The flaws are in the Flattened Image Tree (FIT) signature verification mechanism, which ensures that only trusted firmware images load. Because the vulnerabilities trigger before the operating system starts, they can bypass standard security protections and allow for persistent malware setup. https://beyondmachines.net/event_details/u-boot-bootloader-flaws-allow-stealthy-pre-boot-code-execution-b-d-7-x-u/gD2P6Ple2L #openwrt #cybersecurity #tplink #glinet
0
0
0
T_X @T_X@chaos.social · Jul 10, 2026
ChatGPT/dmesg output also made me aware that this downstream driver fork in #OpenWrt called ag71xx-legacy is not an up-to-date thing, supposedly using some old kernel interfaces? And that the original #ag71xx driver probably never got #SFP initialization stuff (so far). And I also couldn't find anything else with that driver in OpenWrt with an SFP port yet. So looks like one would need to compare some vendor C with what's in OpenWrt maybe. And should substitute some used kernel interfaces. 3/3
0
0
1
gary @gary_alderson@infosec.exchange · Jul 09, 2026
I have a few days off, will try to clarify and focus biz plan, get a site up that reflects objectives/mission, then get llc, start advertising, do the tech consulting but also develop some products opnsense debian malcolm enc persistent nvme in various flavors (debian blends style) that is basically the linecard plus add a sprinkling of pihole consulting, vps/vpn stuff #firewalls #workstations #servers #routers #openwrt #custom fw # ids/ips #pkt cap #dashboards
0
0
0
Junicast @Junicast@chaos.social · Jul 05, 2026
Instead of a #portforward / #nat you shall just open ports with IPv6. If you have a dynamic prefix this is an example of how such rule looks like. So it will even continue to work when you receive a new prefix. Just make sure your DNS keeps pointing to the right address and BAM, you're a server operator, even on a dynamic prefix. Have phun with #OpenWrt and #IPv6
6
0
1
panu @shadowdancer@mstdn.social · Jul 01, 2026
Replying to @stux@mstdn.social
@stux@mstdn.social Yes, on my main router. Running #OpenWRT. My LAN is ad free (well, mostly anyway)
0
0
0