For those (still) running EdgeRouter's - Ubiquiti suprisingly has released new firmware ~ an hour ago.
https://community.ui.com/releases/EdgeMAX-EdgeRouter-Firmware-v2-0-9-hotfix-3/bcbaedc8-41df-4a97-b389-bb122c8905cd
This is a hotfix. Bugfixes -
Fixed CVE-2020-15078 in OpenVPN
Fixed CVE-2022-0778 in openssl
Fixed CVE-2018-25032 in zlib
Fixed CVE-2020-27827 in lldpd
Fixed CVE-2020-13848 and CVE-2021-28302 in libupnp
Fixed command injection in WebUI
With the following know issues -
Known issues -
- [DPI] - Sometimes DPI is reporting wrong rx/tx counters
- [Offloading] - L2TP IPSec traffic is not being offloaded on Mediatek-based routers (ER-X, ER-X-SFP, EP-R6)
- [Offloading] - VLAN traffic is not being offloaded on ER-12