EdgeOS Firmware Changelog ==== Supported products * EdgePoint R6, model: EP-R6 * EdgePoint R8, model: EP-R8 * EdgeRouter X, model: ER-X * EdgeRouter X SFP, model: ER-X-SFP * EdgeRouter Lite, model: ERLite-3 * EdgeRouter PoE, model: ERPoe-5 * EdgeRouter, model: ER-8 * EdgeRouter PRO, model: ERPro-8 * EdgeRouter 4, model: ER-4 * EdgeRouter 6P, model: ER-6P * EdgeRouter 12, model: ER-12 * EdgeRouter Infinity, model: ER-8-XG ==== 1.10.10 (e50, e100, e200, e300, e1000) Changelog / July 24, 2019 ==== Fixes: UNMS - Fix bug when connection with UNMS failed if LLDP was enabled on ER-PoE WebGUI - Fix bug when ER could be DDoSed by opening a lot of unauthenticated WebGUI sessions WebGUI - Fix WebGUI bug when VLAN configuration tab was missing on EP-R6 WebGUI - Fix bad title displayed in browser tab OSPF - Fix memory leak in OSPF when access-list is configured to filter received routes IPsec - Fix potential authorization bypass vulnerabilities in strongSwan (CVE-2018-16151, CVE-2018-16152, CVE-2018-17540) OpenSSL - Fix CVE-2019-1559 security vulnerability in OpenSSL and upgrade OpenSSL to 1.0.1t-1+deb8u11 Bootloader - Add latest bootloader that supports TFTP recovery Kernel - Fix SACK vulnerabilities in TCP networking stack (CVE-2019-11477, CVE-2019-11478) Kernel - Fix excessive resource consumption flaw in TCP networking stack (CVE-2019-11479) Wizard - Fix wrong WAN interface in "Basic Setup Wizard" on ER-X and ER-4 Wizard - Add IPv6 firewall rules by default in "Basic Setup Wizard"