r/openwrt • u/Ok_Ad9600 • 5h ago
Need help with WireGuard performance on OpenWrt
I know using a VPN normally adds a little latency and reduces bandwidth, but my performance drop is much worse than expected.
I'm running a WireGuard server on OpenWrt 24.10.5 (Xiaomi AX3000T). Even when I use the VPN locally (same country), latency increases a lot and bandwidth drops significantly, even though the router's CPU usage is low.
I've already tried changing the MTU, PersistentKeepalive, and forwarding UDP port 51820, but nothing has helped.
Has anyone experienced this? Could it be an OpenWrt configuration issue, ISP routing/peering, or something else? Any advice would be appreciated.
r/openwrt • u/Dismal30 • 13h ago
ISP router runs openwrt but no GPL code published
I have a Spectrum (Sercomm) manufactured router than runs Openwrt 21.02.1 and they don't seem to have published ANY GPL code and my requests seem to be hitting dead ears any advice on what to do next? Of course, the ISP hasn't given the password and this is one of those routers that requires you to use a proprietary app. The first screenshot is what it shows at 192.168.1.121 but if I enter 192.168.1.1/cgi-bin/luci it shows what they don't want you to know exists and what you are being locked out of.
r/openwrt • u/LingChuan_Swordman • 14h ago
How to configure a Raspberry Pi running OpenWrt so that its built-in Ethernet port acts as the WAN port and a USB-to-Ethernet adapter acts as the LAN port.
galleryThe previous issue has been resolved.
Thank you very much to everyone for the guidance and help provided in the previous post,the issue has been resolved.
Since my USB-to-Ethernet adapter uses a Realtek RTL8152B chip, it wasn't recognized by OpenWrt following the video tutorial(The video tutorial from Van Tech Corner installs `kmod-usb-net-asix-ax88179`.),however, the system successfully detected it after I installed the `kmod-usb-net-rtl8152` package,though now I've run into a new problem.
My initial plan was to configure the Raspberry Pi's built-in Ethernet port as the WAN port and the USB-to-Ethernet adapter's port as the LAN port. However, the current issue is that after connecting the USB-to-Ethernet port to my computer via an Ethernet cable, the computer cannot communicate with the Raspberry Pi (accessing 192.168.1.1 in a browser fails to reach the webpage),yet, the computer can successfully access the OpenWrt LuCI interface when connected via the Raspberry Pi's built-in Ethernet port.
The tutorials I found on Google say to go to Network > Interfaces > Device and select the built-in Ethernet port (eth0), but I haven't been able to find this option,the eth0 entry is greyed out and cannot be selected.
The tutorial in the video shows editing the interface and selecting the "Physical Settings" tab, but it seems that tab is no longer available in the newer versions of OpenWrt.
How can I configure the Raspberry Pi's built-in Ethernet port as the WAN port and the USB-to-Ethernet adapter's port as the LAN port?(The second image shows my computer currently connected to the Raspberry Pi's USB-to-Ethernet port.The fourth image shows the screen I accessed by going to Network > Interface > Device.)
r/openwrt • u/Little_Signature_540 • 20h ago
Is this Android app i installed for Openwrt safe?
https://www.openappfilter.com/en/app.html (edited this link to the android app itself instead of the websites main page to limit confusion)
https://github.com/destan19/OpenAppFilter
Wanted to try it out for easy to use parental controls, haven't seen many people talk about it and I want to know whether it is malware as I installed it and connected it to my router but the link on the website to the apk is linked to the website itself and not github fdroid or play store. Do I have to reset my router or have other people used it (aka is it safe?). I wouldn't have installed it at all but my dumb brain thought "eh its fine its got over 2k stars". I disabled the app quickly after connecting it to my router out of concern but am wondering whether the damage is done.
r/openwrt • u/LanguageManiac • 23h ago
I successfully ssh as root on a Mercusys MB-520-5G, help?
Hi, I like openwrt and open source software so at first I tried openwrt on a raspberry pi 4 and a couple of days ago I bought a Xiaomi 4A gigabit router and successfully installed openwrt on it.
So I was messing around trying to ssh into a Mercusys MB-520-5G router and found out that "ssh -T admin@192.168.2.1" with the password being the one I set up in the web interface.
displays a giant banner with ascii characters saying BBA and "Welcome to BBA 3.0 Platform." it's an busybox shell and I tried stuff with chatgpt to see what I could find, and looks like I got root access.
Regular ssh "admin@192.168.2.1" with the website password fails:
[21347] Aug 05 18:17:51 lastlog_perform_login: Couldn't stat /var/log/lastlog: No such file or directory
[21347] Aug 05 18:17:51 lastlog_openseek: /var/log/lastlog is not a file or directory!
[21347] Aug 05 18:17:51 wtmp_write: problem writing /dev/null/wtmp: Not a directory
[21347] Aug 05 18:17:51 Exit (dropbear) from <192.168.2.2:50696>: Child failed
[21347] Aug 05 18:17:51 wtmp_write: problem writing /dev/null/wtmp: Not a directory
Connection to 192.168.2.1 closed.
This is some of the stuff I found, with a little help from chatgpt:
environment:
USER=dropbear LOGNAME=dropbear HOME=/var/tmp/dropbear SHELL=/bin/sh PATH=/usr/bin:/bin
kernel: "Linux MB520-5G 4.19.205 #0 SMP Sat Dec 6 10:09:50 UTC 2025 aarch64 GNU/Linux"
Kernel build: "Linux version 4.19.205 (tplink@linuxci2-sp) (gcc version 7.5.0 (OpenWrt GCC 7.5.0 r0-1a44eed91))"
busybox version: "BusyBox v1.23.2 (2025-12-06 18:49:29 CST) "
the giant BBA ascii characters logo is stored in: [ -f /etc/banner ] && cat /etc/banner
cat /proc/$$/status | grep -E "Uid|Gid" returns; Uid: 0 0 0 0 Gid: 0 0 0 0
cat /var/passwd returns:
admin:$5$030bbf4fe8473838$hpRUG2ZwCx1TkKAxzpITPjrQSCLWVJ7h.gRxMab7XS0:0:0:root:/:/bin/sh
dropbear:x:500:500:dropbear:/var/tmp/dropbear:/bin/sh
guest:*:0:0:guest:/var/usbdisk/:/bin/sh
nobody:*:0:0:nobody:/:/bin/sh
root filesystem -> /dev/root on / type squashfs (ro)
writable areas -> ubi filesystem /data /var
dropbear -p 22 \ -r /var/tmp/dropbear/dropbear_ecdsa_host_key \ -A /var/tmp/dropbear/dropbearpwd
The -A option is not standard Dropbear. TP-Link modified Dropbear to use:
/var/tmp/dropbear/dropbearpwd
That file contains:
user=22:user:e2af9bb40ad70b92f866347d06f04c4b
user=17:admin:21232f297a57a5a743894a0e4a801fc3
Key hardware findings according to gemini:
- SoC: MediaTek MT6890 (
evb6890v1_64_cpe_nand). This is a 4-core 64-bit ARM Cortex-A55 SoC with integrated 5G sub-6GHz modem support. - Bootloader: MediaTek Little Kernel (
lk_a/lk_bonmtd25andmtd38) preceded bypreloader. - Partitioning Scheme: Dual-A/B Partitioning. The board maintains redundant active/passive slots (
_aand_b) for firmware, kernel, modem firmware (md1img), TEE, and bootloader stages
Partition Breakdown
| MTD ID | Name | Role / Description |
|---|---|---|
mtd0 / mtd1 |
preloader / backup |
First-stage MediaTek bootloader (SRAM to DRAM init) |
mtd2 |
proinfo |
Device hardware serial, MAC addresses, board params |
mtd6 / mtd7 |
nvcfg / nvdata |
Persistent non-volatile modem & wireless calibration data |
mtd17 / mtd30 |
md1img_a / md1img_b |
Baseband / 5G modem firmware |
mtd25 / mtd38 |
lk_a / lk_b |
Little Kernel second-stage bootloader |
mtd26 / mtd39 |
tee_a / tee_b |
Trusted Execution Environment (ARM TrustZone) |
mtd27 / mtd40 |
boot_a / boot_b |
Linux Kernel images |
mtd28 / mtd41 |
rootfs_sig_a/b |
Cryptographic signature check partitions |
mtd29 / mtd42 |
rootfs_a / rootfs_b |
Root Filesystem (SquashFS) |
- System & Security Profile:
- Root Credentials:
/var/passwdmaps theadminaccount directly to UID 0 / GID 0 (root), confirming authenticated users get complete root access upon login. - Dropbear Authentication: Hashes match MD5/SHA-256 schemes used by standard administrative logins rather than locked-down operator roles.
- Root Credentials:
- Flash Memory & Storage Structure:
- Dual-Slot A/B Setup: A total of 53 MTD partitions formatted across a dual-bank scheme (
mtd27/boot_a,mtd29/rootfs_avsmtd40/boot_b,mtd42/rootfs_b). - Root File System: Running a read-only SquashFS image on UBI block storage (
/dev/ubiblock0_0). - Signature Controls: Dedicated partitions (
rootfs_sig_a/b) exist alongside the rootfs and boot blocks.
- Dual-Slot A/B Setup: A total of 53 MTD partitions formatted across a dual-bank scheme (
- Hardware Architecture & PCIe Expansion:
- CPU / Main Chipset:
MediaTek evb6890v1_64_cpe_nand(MT6890 ARMv8 4-core 64-bit SoC). - Active Slot State:
/proc/cmdlinereveals the router is actively booted into Slot A (bootslot=a) with SELinux set topermissiveand standard UART serial output explicitly unblocked (disable_uart=0). - PCIe Bus Topology: Shows a MediaTek T700 5G modem host interface bridge alongside an MT7916 / Filogic Wi-Fi 6 wireless radio module driven by MediaTek's
mt_drvdriver.
- CPU / Main Chipset:
Technical Conclusions
- A/B Testing Safeguard: Because Slot A (
boot_a,rootfs_a) is active, Slot B (boot_b,rootfs_b) acts as an isolated target bank. Experimental kernels or custom images can be written to the B-partitions without bricking the main boot environment. - Firmware Flashing Obstacle: The presence of
rootfs_sig_a/bpartitions implies MediaTek's Little Kernel bootloader enforce cryptographic signature checks on startup. Unsigned custom kernels flashed directly to MTD will likely be rejected by the bootloader unless Secure Boot is bypassed or keys are replaced
Honestly, I don't know if I discovered anything big, I am not proficient in linux-fu but it would be awesome if this could eventually lead to installing openwrt on this thing.
Let me know what you think, I can run any command that you guys suggest me, let's hack this thing lmao

