Peplink Firmware 8.6.0: New Features and Upgrade Notes

Peplink Firmware 8.6.0

Peplink has officially released Router Firmware 8.6.0, and it is one of the more substantial feature releases we have seen in the 8.x line. Released on July 29, 2026, this build touches nearly every part of the Peplink platform (SpeedFusion, cellular, Wi-Fi, eSIM, security, and the Synergy architecture), and it carries hundreds of fixes accumulated across the 8.5.x maintenance stream.

Below we break down what is new, what changed under the hood, and what you need to know before you hit the upgrade button.

Read This Before You Upgrade

There are several important notices that apply to this release, and a couple of them can bite you if you skip them.

Staged upgrade required on certain models. The following devices must be running Firmware 8.5.4 before you can move them to 8.6.0:

  • BR Series: BR1 Pro (CAT-20), BR1 Pro 5G, BR2 Pro
  • All Dome, Transit, and B One models

If you are running something older on these units, upgrade to 8.5.4 first, then to 8.6.0.

FIPS and IPsec preshared keys. When FIPS is enabled, IPsec VPN preshared keys must now be at least 14 characters long. Existing IPsec profiles with shorter keys may fail to connect until they are updated. If you run FIPS-enabled sites with older tunnel configurations, audit your preshared keys before scheduling the upgrade window.

Certificate and key requirements have tightened. Firmware 8.6.0 raises the bar on security standards, and weak certificates and keys such as DSA, short RSA keys, and legacy PKCS#12 files are no longer supported. If the device detects an outdated certificate, it automatically falls back to the secure default certificate to keep the connection protected. That is a safe behavior, but it also means a custom certificate you were relying on could quietly stop being used. Review the Certificate Manager after upgrading and replace anything outdated.

Some models have reached the end of the line. Starting with 8.6.0, the following are no longer supported and will only receive 8.5.x maintenance releases going forward:

  • Balance: 30 LTE HW, 30 Pro HW1, 210 HW4-5, 310 HW4, One HW1-3, One Core HW1
  • MAX: 700 HW3-4, BR1 ENT HW1-2, HD1 Dome HW1, HD2 HW5-6, HD2 Dome HW1, HD2 IP67 HW2-5, HD2 Mini HW1-4, HD2 with MediaFast HW1-4, HD4 HW1-5, HD4 IP67 HW1, HD4 with MediaFast HW1-4, Transit HW1-3, Transit 5G HW2-3, Transit Core HW1, Transit Duo HW1-3, Transit Duo Pro E HW1, Transit Pro E HW1
  • MediaFast: 200 HW1, 200 HW3
  • SpeedFusion Engine: SFE CAM HW1

The Headline Features

SpeedFusion Boost

The feature we expect to generate the most interest is SpeedFusion Boost, which improves application performance over SpeedFusion connections using Starlink, 5G, and other suitable WAN links. Starlink and 5G both deliver enormous raw throughput but suffer from variable latency and jitter, which are the exact conditions that degrade real-time applications. Boost is designed to smooth that behavior out over the SpeedFusion tunnel so that latency-sensitive traffic behaves more predictably on links that would otherwise be too inconsistent to rely on. If you have deployed Starlink alongside cellular and been frustrated by inconsistent VoIP or video performance, this is the feature to test first.

WireGuard for Remote User Access

Peplink has added WireGuard as a Remote User Access VPN option on all models. WireGuard has become the modern standard for remote access VPN thanks to its small codebase, strong cryptography, and dramatically faster connection setup compared to legacy protocols. Adding it alongside the existing OpenVPN and L2TP options gives administrators a much better story for remote workers and roaming devices, particularly on mobile clients, where WireGuard’s ability to survive network changes without dropping the tunnel is a real advantage.

SFC Direct Access

Direct Access support for the SpeedFusion Connect App lets users connect directly to supported routers from the SF Connect App. This simplifies remote access for users who need to reach resources behind a Peplink router without a full site-to-site tunnel or a traditional VPN client deployment.

OneWeb Integration

Firmware 8.6.0 adds OneWeb integration support on all models except the HD1 Dome Pro. With LEO satellite becoming a mainstream WAN option for maritime, remote industrial, and mobile deployments, native OneWeb support means the router can monitor and manage that link as a first-class WAN rather than treating it as a generic Ethernet connection.

RADIUS over TLS (RadSec)

For enterprise Wi-Fi deployments, RadSec support is a meaningful addition. Traditional RADIUS traffic uses UDP with a shared secret and offers limited protection in transit. RadSec wraps RADIUS in TLS, which matters a great deal when authentication traffic crosses the public internet, a common situation for distributed sites authenticating back to a central identity provider. This is supported across Balance 20X, 310 Fiber 5G, 310 5G HW3, all Dome, MBX and UBR models, most of the BR line, and all Transit, Orbit, and B One models.

Cellular, 5G, and eSIM Improvements

The cellular side of this release is deep, and it is where most Peplink deployments live.

Multi-APN support is now available on 5GN devices, allowing a single cellular modem to establish multiple APN connections. This is a big deal for deployments that need to separate management traffic from user traffic, or that use a private APN alongside a public one.

IPv6 on cellular has been extended to a wide range of devices with 5GD, 5GH, 5GK, 5GN, and GLTE-S product codes, and there is new support for configuring IPv6 SLAAC/DHCPv6 connection mode for Ethernet WAN. As carriers continue to push IPv6-first deployments, this closes a gap that has caused headaches on certain networks.

5G SA (Standalone) support has been added for 5GD cellular modules, and there is now control over 5G SA Carrier Aggregation on 5GK and 5GN modules. Firmware 8.6.0 also supports upgrading 5GN modules to cellular firmware that includes RED DA support and improved 5G SA network compatibility.

On the eSIM front, this release is a significant step forward:

  • Support for up to four eSIM profiles per cellular module
  • Support for the newer GSMA eSIM profile format used by some providers
  • Improved Peplink eSIM carrier name display for easier identification of the connected network
  • BYO eSIM details are now displayed in Synergy mode
  • Fixed SIM failover so devices can switch to the Peplink eSIM when cloud access is unavailable
  • Fixed missing monthly and billing history for BYO eSIM and Peplink eSIM usage records

Other useful cellular additions include configurable 5G signal strength thresholds, a one-click option to erase all SMS messages stored on a SIM, SMS control messages sent through supported SIM provider portals, and improved cellular WAN startup time after boot, the latter coming from skipping an unnecessary carrier selection command when automatic selection is already active.

Synergy Mode Gets Serious

Synergy Mode, where one router acts as a controller for the WAN resources of another, has received a lot of attention in this release:

  • A new Synergy WAN transport mode setting lets you choose between Performance and Compatibility modes
  • Up to 40 Synergy WAN connections are supported on selected models
  • Wi-Fi APs on Synergized Devices can now be managed through the AP Controller
  • A secure fallback certificate was added for Synergy TLS connections to maintain compatibility with older peers

Several Synergy bugs were also resolved, including WAN mapping and status becoming incorrect after configuration changes without a reboot, Synergy links disconnecting during Speedtest or when the Synergy WAN was saturated, and Synergy WAN using VLAN WAN mapping to the wrong physical interface on module-based models.

Networking, Routing, and Firewall

There is a long list of practical improvements here that will matter to anyone managing complex networks:

  • Virtual Network Mapping for inter-VLAN traffic, including mappings to virtual IPs that overlap with VLAN subnets
  • MAC address whitelist support for Layer 2 SpeedFusion tunnels, including MAC prefix matching
  • An “Advertise Routes to Peer” setting for NAT Mode SpeedFusion VPN, so route advertisement to remote peers can be disabled
  • SpeedFusion VPN Route Isolation on FusionHub
  • Support for up to 1000 SpeedFusion peers on B1350 EC devices
  • Static routes that resolve through a domain name
  • BGP default route import and BGP-to-OSPF default route redistribution, plus the ability to import BGP routes only when they originate from a specified ASN
  • IEEE 802.1p CoS values on VLAN-tagged and virtual VLAN WAN interfaces
  • Per-WAN bandwidth limiting so configured upload and download limits are enforced on actual traffic
  • Firewall log entries now include the matching rule name, a small change that saves real troubleshooting time
  • Logging for sessions blocked by IDS and DoS protection
  • Improved OpenVPN traffic detection in DPI, including traffic on non-standard ports
  • SHA2-384 authentication for IPsec VPN Phase 2

Monitoring, Management, and Visibility

  • Starlink status information has been added to WAN Details, and Starlink WAN health checks now use 8.8.8.8 and 1.1.1.1 when the DNS-based health check options are selected or no health check host is configured
  • WAN status summary logs and WAN failover event logs for entering and exiting backup state
  • WAN names added to Status > Ethernet Port Details and the API
  • Customizable SNMP trap alerts for key device health and cellular events, plus GPS information export through SNMP
  • A new CLI command to display cellular status across supported modem types
  • API support for uploading and downloading configuration files using token-based authentication
  • InTouch monitoring of USB serial adapters and connected serial ports, so InTouch can report connection state and timeout events

Wi-Fi and AP Controller

  • Tri-band external and integrated AP support in the AP Controller
  • PPSK names in the wireless client list, so admins can see which passphrase each client used
  • Metered Wi-Fi connection advertisement in beacon frames for AP and controller-managed SSIDs
  • The ability to enable or disable specific Wi-Fi data rates on each AP radio
  • Improved Wi-Fi WAN roaming to reduce interruptions during handoff
  • WPA2/WPA3 Personal is now the default SSID security mode on supported Wi-Fi AP devices

Hardware and Platform Additions

  • Jumbo Frame support on selected models including Balance 310, 580X HW2, 310 5G HW3, all Dome models, BR1 Pro (CAT-20), BR1 Pro 5G, BR2 Pro, and all Transit, Orbit, and B One devices
  • LACP support on the Balance 580X HW2
  • Dedicated Management Port configuration in LAN Port Settings on the Balance 2500, 1350 EC, 2500 EC, and 5000 EC
  • Automatic Ethernet detection on all USB modem ports
  • GPIO-triggered factory reset
  • Serial Interface support in Local Service Firewall rules, so serial port access can be controlled by firewall policy
  • Edge Compute on B One Series devices when PrimeCare is active
  • Permanent FIPS support on eligible devices
  • One included Virtual WAN on VLAN for eligible router models with an active Care plan
  • Ethernet port status monitoring for BR1 Mini 5G models

Notable Bug Fixes

With 23 pages of resolved issues, we cannot cover everything, but here are the fixes most likely to matter to real deployments.

Security fixes. Peplink resolved a CLI vulnerability that could allow command injection, a Web Admin vulnerability that could allow unauthenticated access to internal binaries, updated SSH CLI components to address multiple security vulnerabilities, and updated web service components to address CVE-2026-42945. These alone are a strong argument for planning your upgrade.

Stability fixes. Several long-standing stability issues were addressed, including a LAN/WAN interface crash under sustained packet flooding on BR2 LTE devices, modem monitoring crashes and system hangups on BR2 devices, unexpected restarts on the Balance 580X HW2, a QoS issue affecting system stability, a stability issue during certain packet processing conditions, a system stability issue when processing DNS inspection traffic, and, notably, an issue where applying changes might cause the device to revert to factory default settings.

Cellular fixes. Cellular WAN not reconnecting after a data connection failure, cellular WAN DHCP lease renewal failing intermittently, devices selecting the wrong SIM when SIM detection hardware was unavailable, 5GH cellular missing cellular mode information and failing to start a data connection, delayed cellular reconnection after switching network modes, intermittent SMS sending failures on LTE-E, and carrier-specific fixes for Yettel Bulgaria, A1 Bulgaria, France Orange, Celona, and Rakuten Mobile.

SpeedFusion and VPN fixes. DNS resolution over SpeedFusion stopping after WAN connectivity is restored, SpeedFusion profiles not loading after an HA master reboot when no WAN is available, OSPF routes learned over SpeedFusion incorrectly conflicting with local VLAN routes, ARP requests for Layer 2 SpeedFusion static route gateways being dropped, profiles stuck in “Updating Routes…” after a firmware upgrade, IP passthrough breaking after enabling Layer 2 SpeedFusion VPN, and an IPsec status check that could make the device unresponsive.

Wi-Fi fixes. Clients remaining connected but experiencing very low or zero throughput when the signal became weak, radios failing to start correctly when auto channel width was used on certain channels, and 32-character SSIDs not displaying correctly in SSID usage reporting.

High Availability fixes. HA failover not following the “Resume Master Role Upon Recovery” setting (including in no-WAN environments), the HA LAN administration IP not updating after a LAN IP change, and improved HA configuration synchronization with the update interval reduced to two minutes.

Other fixes worth noting. Drop-in Mode failing to detect or reach hosts on the WAN subnet, DHCP relay not forwarding requests to all configured DHCP servers, USB mobile WAN not working on USB 3.0 ports, USB WAN port assignment and DNS settings reverting after reboot, switch port PVID changes not applying and switch port settings reverting after a controller reboot, captive portal not appearing with Internet access unavailable, DNS over HTTPS connectivity with Quad9 servers, Docker containers consuming excessive CPU, GPS RMC output corruption after week rollover handling, and offline LAN devices incorrectly showing as online in client status reporting.

Known Issues

Peplink has documented a handful of open items in this release:

  • Air Monitor does not work on selected Wi-Fi AP devices
  • Docker containers cannot run on a device without an active DHCP server
  • LAN clients on ports 1 or 2 may fail to obtain an IP with Multiple IP passthrough WAN support
  • YouTube blocking may not work when YouTube traffic uses QUIC

Frequently Asked Questions

Do I have to upgrade to 8.5.4 before installing 8.6.0?

Only on certain models. The BR1 Pro (CAT-20), BR1 Pro 5G, BR2 Pro, and every Dome, Transit, and B One model must be running Firmware 8.5.4 before moving to 8.6.0. All other supported devices can upgrade directly.

Will 8.6.0 break my existing IPsec tunnels?

Only if you run FIPS. With FIPS enabled, IPsec VPN preshared keys must now be at least 14 characters. Profiles with shorter keys may fail to connect until the keys are updated. Non-FIPS deployments are unaffected by this specific change.

What happens to my custom SSL certificate after the upgrade?

If the device detects an outdated certificate such as DSA, a short RSA key, or a legacy PKCS#12 file, it automatically falls back to the secure default certificate. Your device stays protected, but your custom certificate stops being used. Check the Certificate Manager after upgrading and install a modern replacement.

My router is not on the supported list. What now?

Devices on the end-of-support list, including the Balance 30 LTE, Balance One, MAX HD2 and HD4 hardware revisions listed above, MediaFast 200, and SFE CAM HW1, will continue to receive 8.5.x maintenance releases as needed. They simply will not get 8.6.0 features. If you are on one of these, it is a good time to talk about a replacement path.

Does SpeedFusion Boost require a specific license or plan?

SpeedFusion Boost is listed as supported on all models in 8.6.0. Keep in mind that InControl must be enabled on PrimeCare devices for software features such as SpeedFusion Bonding, Smoothing, and Hot Failover to update properly.

Should I upgrade right away?

The security fixes in this release, including a CLI command injection vulnerability, an unauthenticated Web Admin access vulnerability, and CVE-2026-42945, make a strong case for upgrading sooner rather than later. That said, test on one device with out-of-band access before rolling it out across a fleet.

The 5Gstore Take

Firmware 8.6.0 is a feature-rich release with real security value behind it, but it is also a major version with tightened certificate requirements and a staged upgrade path on several product lines. It is not a firmware you push to 200 sites on a Friday afternoon.

Here is how we would approach it:

  1. Confirm your upgrade path. BR1 Pro (CAT-20), BR1 Pro 5G, BR2 Pro, and all Dome, Transit, and B One models must be on 8.5.4 first.
  2. Audit your certificates in the Certificate Manager before upgrading, and replace anything using DSA, short RSA keys, or legacy PKCS#12.
  3. Check IPsec preshared keys if you run FIPS-enabled sites. Anything under 14 characters needs attention.
  4. Test on one device first, ideally at a site where you have out-of-band access, before rolling firmware out fleet-wide.
  5. If you use FusionSIM or RemoteSIM, Peplink also suggests upgrading the SIM Injector to Firmware 1.2.6.

For most customers, the combination of security patches, cellular stability fixes, and the eSIM improvements makes this a worthwhile upgrade, just do it deliberately. The features we are most excited to see in the field are SpeedFusion Boost on Starlink-plus-cellular deployments and WireGuard for remote user access, both of which solve problems customers ask us about constantly.

If you are not sure whether 8.6.0 is right for your deployment, or you need help planning an upgrade across a fleet of devices, the 5Gstore team is here to help. We work with these products every day and can advise on upgrade sequencing, feature compatibility, and which models in your inventory are affected by the end-of-support list. Alongside Peplink we also carry and support Cradlepoint, Teltonika, Semtech, Inseego, Digi, and Katalyst hardware, so if the end-of-support list means it is time to plan a replacement, we can walk you through the options across every brand we stock.

Browse our full Peplink lineup at 5Gstore, see what else is new on the 5Gstore blog, or contact us and we will help you sort it out before you touch production.

Michael Ginsberg, founder of 5Gstore.com

About the Author

Michael Ginsberg is the founder of 5Gstore.com, a trusted source for cellular routers and failover networking solutions since 2005. With a background in software and networking dating back to 1988, he writes about cellular connectivity, IoT infrastructure, network security, and fleet management. Connect with Michael on LinkedIn or reach the 5Gstore team through our contact page.