Router Over-the-Air Updates vs OpenWrt: When the ISP Image Is the Vulnerability
Lars Beckmann
September 18, 2026
The ISP router updates itself. That sentence is sold as hygiene. Sometimes it is. Sometimes the image that landed at 3 a.m. re-enabled remote management, reset a firewall rule you did not know was a vendor “feature,” or shipped a four-year-old OpenSSL because the carrier’s test lab still has a ticket open. The update channel is a privilege. On a box you do not control, that privilege belongs to a company whose threat model is “keep the fleet identical,” not “keep your homelab VLAN boring.”
I have been running OpenWrt on home infrastructure for years. I still leave an ISP modem in bridge when I can. I do not leave my only firewall on their image if I can put a used box in front. This is not romance about compiling. This is what OTA means when the signer is a cable company.
What ISP OTA is for
Carriers need to kill a bug across a million gateways. They need to push a Wi-Fi patch, a TR-069 change, a new ACS URL. They do that with images you cannot inspect and a schedule you cannot decline on many consumer units. When it works, your aunt gets a fix she would never flash. When it fails, a town loses IPv6 or gains an open 7547. You will read about it on a forum after your cameras drop.
The image is also how they enforce the product: captive upsells, a DNS that is theirs, a guest network that phones home. An “update” can be a policy. I have seen remote admin come back after a patch because the default in the new tree was on. The changelog said “stability.”

What OpenWrt OTA is not
OpenWrt has attended sysupgrade. You fetch an image you chose, you keep settings or you do not, you watch it come back. There is no carrier silently rewriting your firewall at 3 a.m. unless you built that. There is also no one whose job is to patch your particular used travel router next Tuesday. You are the fleet. That is the trade.
Attended upgrades are slower and safer for a homelab that has VLANs. Unattended OpenWrt upgrades on a box that is the only path to the internet are how you learn about image sizes and boot partitions at an inconvenient hour. I upgrade on a Saturday with a second path: phone hotspot, a spare travel router, a note of the last-good image.
The vulnerability on OpenWrt is you: a package from a year ago, a luci that you did not update, a password you never changed, WAN exposed because you wanted “just one port.” The vulnerability on the ISP image is them plus you. You cannot patch their remote-management daemon. You can unplug it from being the router.
When the ISP image is specifically the problem
Known classes, without turning this into a CVE recitation: TR-069/CWMP left reachable; default Wi-Fi creds derived from serials; UPnP on by default after a “reset to fix your Wi-Fi” update; IPv6 firewall holes that appear when they enable a new prefix mode; vendor cloud features that punch outbound and then inbound. An OTA that “improves the app” is often a new cloud. Your threat model may not include their app.
If the modem must stay for the WAN handoff, bridge it. Let their OTA own a brick that only speaks to the ISP. Let OpenWrt own DHCP, DNS, VLANs, and the Wi-Fi you care about — or let OpenWrt be the router and use dumb APs. I have converted mesh kits into wired APs for that reason. The ISP box can update itself into a pumpkin. The pumpkin is only a modem.
Some ISPs fight bridge. Then you double-NAT and you complain, or you put OpenWrt in the DMZ if they have one, or you change ISPs. I will not tell you double-NAT is fine for everything. I will tell you it is better than their remote admin on the same box as your IoT VLAN.

Mesh kits and the second OTA
Consumer mesh — Eero, Orbi, the ISP’s own pods — has a second update religion. The app updates nodes so they stay a product. That is convenient and it is how a VLAN story dies. Isolation toggles lie after a firmware that “simplified” guest Wi-Fi. If the homelab needs an IoT VLAN that survives roaming, I would rather wired OpenWrt APs than a mesh that OTAs into a flat LAN. I have done that conversion. The Saturday is cheaper than the month of dropouts after their cloud push.
If you keep the mesh, treat their OTA like the ISP’s: check after it happens, do not put the only DNS on their node, and do not assume last month’s setting survived. Screenshot the app. I am not joking. The app will not show a diff.
Supply chain, briefly
OpenWrt images from the project are a known tree. Vendor images are a tree you cannot clone. Both can ship bugs. Only one lets you read the commit that broke DSA. I sleep better reading a commit than reading a carrier PDF that says “enhanced security.” Enhanced is a vibe. A commit is a fact.
I still verify checksums. I still do not download a “custom OpenWrt” from a random blog for a cheap travel router. That is how you install someone else’s OTA. The point of leaving the ISP image is not to pick up a stranger’s.
When I keep the ISP image
Rentals, short stays, households that will not accept a second box, and links where the carrier disables the circuit if they do not see their gateway. I then turn off every cloud toggle I can find, change the admin password, disable WPS, and I do not put the homelab behind that box without a second firewall if I can sneak one in. I accept that an OTA may undo the toggles. I check after outages.
I also keep their image when I am not the person who gets the 3 a.m. call. A parent on a carrier gateway that updates is a parent who still has a Wi-Fi password on the fridge. OpenWrt there is a hobby I would be on the hook for.
When I flash OpenWrt
When the box I own is the firewall. When I need VLANs that survive a vendor “feature.” When I want DNS to be mine. When I have a model with a good OpenWrt page and a recovery path I have practiced. When I am willing to own the upgrade.
I do not flash a gateway that is also the modem if I cannot recover the WAN. I buy or reuse a dedicated router. The $30 used box is cheaper than a night without a circuit because I bricked the ONT’s friend.
I also look at the Table of Hardware before I buy. A pretty case with no recovery, a 16 MB flash that cannot hold a current image, a media chip with a driver that is “community, maybe” — those are how people end up on a Discord at midnight asking why the WAN LED is dark. The ISP image is ugly. It is also a known boot. OpenWrt is only an upgrade if the hardware page is boring in the good way: supported, documented, a failsafe that someone besides the original poster has used.
Wifi on OpenWrt is a separate honesty check. Some chips are fine. Some chips are why you keep their APs and only replace the router. I have done that split more than I have done a full flash of every radio in the house. The vulnerability I care about is the firewall and the management plane, not whether the 6 GHz radio is 3% slower. If the radios on the used box are a science project, I leave them off and run dumb APs I already trust.
What I actually change after the first boot
Password, then the LAN I meant, then DNS that is not theirs. I turn off services I will not use: uhttpd on WAN if I ever fat-finger a rule, UPnP unless I have a reason, IPv6 until I have a prefix plan. I do not install every luci app on day one. Packages are how an attended upgrade becomes an unattended mess of leftover config.
I write the WAN type down. PPPoE credentials live in a place I can reach if the box is in failsafe. VLAN IDs for the ISP, if they use them, go next to the checksum. This is the same restore-note habit that makes a homelab survive a Saturday. Without it, OpenWrt is just a more honest way to lock yourself out.
I do not expose luci. I do not expose SSH on WAN. If I need in from away, I use a tunnel I already run — Tailscale, WireGuard to a host that is not the router if I can help it. Putting the management plane on the same public address the carrier used for TR-069 is how you recreate their vulnerability with better branding.
A recovery drill that belongs next to the flash
Before I sysupgrade a box that is the household’s only router, I print or save: last-good image filename, checksum, the failsafe dance for that model, and a phone hotspot password. I do this because I have skipped it and then stood in a hallway holding a USB-serial I could not find. ISP OTA has a recovery path too: they ship you a new gateway in three days. That is not a drill. That is a ticket. I prefer a drill I own even when it is ruder.
If you cannot name the failsafe key combo, you are not ready to leave their image. Stay bridged, or stay on their router, until you can. OpenWrt without recovery is how hobbyists create outages that make the ISP image look kind.
The decision
OTA is a virtue when you trust the signer and the defaults. ISP images fail that test often enough that I treat their update as a potential vulnerability, not as a comfort. OpenWrt moves the vulnerability to my calendar. I prefer a calendar I can see. If you cannot see theirs, do not let theirs be the only firewall. Bridge, isolate, or replace. Then update on purpose. I still take their modem updates. I do not take them as my security story.