// Engineering Log
OpenWrt: an alternative router firmware — what it can do and how to install it
Published on 2026-09-22
// Fast route
This article belongs to the topic Servers and infrastructure.
OpenWrt is a free Linux-based firmware for routers and other network devices. It replaces the factory firmware and turns a router into a full system with a package manager: you can run a VPN, split the network into segments, set up traffic prioritization and ad blocking. The current branch is 25.12: the first release 25.12.0 was released on March 5, 2026 and supports over 2,200 devices; as of September 2026 the latest version of the branch is 25.12.5.
What OpenWrt gives you
- Updates instead of abandoned firmware. Manufacturers often stop releasing updates for routers after two to three years. OpenWrt continues to support many models after that.
- Packages. The system is assembled from packages, and needed functionality is installed as required: WireGuard, OpenVPN, DNS-over-HTTPS, monitoring, a file server on a USB drive.
- Flexible networking. VLAN, multiple SSIDs with different rules, a guest network isolated from the main one, policy-based routing.
- SQM (Smart Queue Management) — queue management that reduces latency when the link is saturated: a video call won’t drop while someone is downloading a large file.
- Ad blocking at the DNS level for the whole network — with the adblock package or in combination with a separate server like Pi-hole.
The web interface is called LuCI, settings are stored in text files in the /etc/config directory, and everything done in the interface can be done from the command line over SSH.
What changed in 25.12
- apk package manager instead of opkg. The fork of opkg that the project used is no longer maintained. The commands change:
apk update,apk add package,apk del package. - Attended sysupgrade is built into the system: the upgrade is assembled on the project’s server together with the already installed packages and applied in a single action.
- Linux kernel 6.12, Wi-Fi scripts rewritten in ucode, shell command history is preserved between sessions.
An important warning from the OpenWrt documentation: do not upgrade all packages with apk upgrade. Some packages have incomplete dependencies, and such an upgrade will sooner or later brick the device. The correct way to upgrade the system as a whole is via LuCI Attended Sysupgrade, the owut utility, or the Firmware Selector on the project site.
How to install
Installation depends on the model, and there is no universal method. The procedure is:
- Find your model in the Table of Hardware on openwrt.org and open its page. The exact hardware revision matters: different revisions of the same model (v1 vs v2) can be completely different devices. The revision is usually indicated on the sticker on the bottom.
- Check the requirements. Modern versions need sufficient flash and RAM; models with too little memory are marked separately in the list.
- Download the correct image. For the first installation from the factory firmware use the factory image. The sysupgrade image is only needed to update an already installed OpenWrt.
- Install using the method described on the model page. For many devices this is the “Firmware Update” item in the factory web interface; for others — TFTP recovery or loading via the serial console.
- After booting, connect to
192.168.1.1, set the admin password and only then configure the rest.
The main mistake is flashing the sysupgrade image through the factory interface or using an image for a different revision. In the best case the firmware will reject it; in the worst case the router will stop booting, and you will have to recover it using the method from the same Table of Hardware page.
Example: WireGuard for access to the home network
After installing the packages (apk add wireguard-tools luci-proto-wireguard) the WireGuard interface type appears in LuCI. Next steps:
- create an interface, generate keys, set the tunnel network address;
- add peers — phones and laptops — with their public keys;
- allow the incoming WireGuard UDP port in the firewall and assign the interface to the
lanzone or to a separate zone with the required rules.
Risks and limitations
- Loss of warranty and manufacturer support. Installing third-party firmware usually voids official support.
- Wi-Fi may perform worse than the factory firmware on some models: not all chips have open drivers with full functionality.
- Updates are your responsibility. A router with outdated OpenWrt is as vulnerable as one with factory firmware.
- Not every router should be flashed. For an office where manufacturer support and easy replacement are required, a turnkey solution is more practical — MikroTik or Keenetic.
When OpenWrt is suitable
OpenWrt is a good choice when you have a suitable router you don’t want to throw away, when the factory firmware hasn’t been updated for a long time, or when you need features that it lacks: WireGuard, SQM, VLAN, a custom DNS. It fits a small office with one or two ISPs and the requirement “just works” if there is someone in the company willing to maintain it.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Servers and infrastructure
VPS, Linux, web stack, migrations, hosting, databases, and core operations.
Typical tasks behind this topic
- Move a site or service to a new server
- Set up Linux, Nginx, databases, and backups
- Figure out why the system behaves unstably
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related