This is release 3.89.11.20260919 of OpenCCU which is a security bugfix release with the following bugfixes and feature changes:
π§ Changes:
For all changes, see the full commit log.
π CCU/homematicIP Service Changes
- bump OpenCCU-Base to 3.89.11 (#4202, @jens-maus) including the following changes:
- added input validation and sanitization for JSON-API calls creating system variables (homematicip/OpenCCU-Base#13)
- sanitized HomeMatic Script variable identifiers and improved argument escaping (homematicip/OpenCCU-Base#14)
- added HTML escaping for system variable data displayed in the WebUI (homematicip/OpenCCU-Base#13)
- hardened
user.setLanguageby avoiding shell command execution and sanitizing the target profile filename (homematicip/OpenCCU-Base#13) - raised
system.saveObjectModelaccess level to USER ((homematicip/OpenCCU-Base#14)
- Refresh stale OpenCCU-Base rootfs patches to restore zero-fuzz CI applicability (#4191, @jens-maus)
- Refresh 0035 SysVar popup patch for OpenCCU-Base 0ca8906 (#4187, @jens-maus)
- openccu-base: add options to leave out ReGaHss and the WebUI (#4183, @hobbyquaker)
π WebUI Changes
- webui: hide empty/missing CPUMHZ in help.cgi (#4181, @jens-maus)
- fix: use deterministic daemon CWD and harden Tcl dlopen handling (#4200, @jens-maus)
- fix EULA files to open link in tabs/new windows instead (#4178, @jens-maus)
π₯οΈ Operating System Changes
- fix
/etc/profile.dvariables to omit empty vars (#4199, @jens-maus) (#4200, @jens-maus) - bump kernel-upstream to 6.18.52 (#4182, @jens-maus)
- bump rpi-eeprom to 811685a (#4184, @jens-maus)
π Other Changes
- Add
openccu-base.hashand automate hash refresh in dependency updater (#4201, @jens-maus) - remove obsolete host-openjdk-bin dependency (#4192, @jens-maus)
- Limit rpi-eeprom bumps to firmware changes and surface pieeprom versions in update PRs (#4195, @jens-maus)
π Support:
For support on installation and help please visit the following web pages:
OpenCCU – Documentation πΊπΈ
OpenCCU – Discussions πΊπΈ
OpenCCU – Dokumentation π©πͺ
OpenCCU – Forum π©πͺ
π¦ Download:
The following installation archives can be downloaded for different hardware platforms. To verify their integrity a sha256 checksum is provided as well. You can either upload these files using the WebUI-based update mechanism or unarchive them to e.g. flash the included *.img files on a fresh installation media (e.g. microSD card):
RaspberryPi5 Model B β (installation):
π¦ OpenCCU-3.89.11.20260919-rpi5.zip
SHA256: faacfd87cec320e72ff60932fd3c1df1431d428d30e297f851ead3751eea9c1dRaspberryPi4 Model B, RaspberryPi Compute Module 4, RaspberryPi 400 β (installation):
π¦ OpenCCU-3.89.11.20260919-rpi4.zip
SHA256: 95273fa4fa53fda4ab792c38c9739234919842c4719ff81447f4d88b55e5f168CCU3, ELV-Charly, RaspberryPi3 Model B+, RaspberryPi3 Model B, RaspberryPi3 Model A+, RaspberryPi Compute Module 3, RaspberryPi Compute Module 3 lite, RaspberryPi Zero 2 W β (installation):
π¦ OpenCCU-3.89.11.20260919-rpi3.zip
SHA256: b28bf75cddc14cc9492882d069367e0d182b95aa81ad99d9cac21a7bc255d024
π¦ OpenCCU-3.89.11.20260919-ccu3.tgz (only for initial CCU3 Firmware -> OpenCCU Upgrade)
SHA256: 034f0dcd99ac8dcf332bae9afc12ca07906997db46793bd9ff4da7af70aa3a76ODROID-N2/N2+/C4/C2 β (installation):
π¦ OpenCCU-3.89.11.20260919-odroid-n2.zip
SHA256: fdcb7d7a2bac020791027bc11a7a1d17c96363bc10fee9ce64ff8f9c8e8d2c45
π¦ OpenCCU-3.89.11.20260919-odroid-c4.zip
SHA256: 14d609d2858bfdbceefa13871cc3bf4d3389910515079e34e36c1c0b3ea52fe4
π¦ OpenCCU-3.89.11.20260919-odroid-c2.zip
SHA256: 1b088cddd24192aaee880e25e94ae51f6e9d0c3efa234e2f770b831b200abecbASUS Tinkerboard 2/2S β (installation):
π¦ OpenCCU-3.89.11.20260919-tinkerboard2.zip
SHA256: f323d9d4838e4f903a72417c47a8413a3c9cd967dadb8f621626905cfd711b11Generic-x86_64 β (installation):
π¦ OpenCCU-3.89.11.20260919-generic-x86_64.zip
SHA256: 91e18cb1b2d6c04f2df1229488c803b3deb83fc5d662f423a83898c9f6cd5827Open Virtual Appliance (OVA) β (ProxmoxVE, VirtualBox, ESXi, Synology, QNAP, Workstation Player, QEmu, UNRAID, HyperV):
π¦ OpenCCU-3.89.11.20260919-ova.zip
SHA256: f68c1acb8ea55e24f4dccfe5f8c5251f97bde69c43dfb7518c6b8f5a37332cdf
π¦ OpenCCU-3.89.11.20260919.ova (only for initial OVA installation)
SHA256: 3a6b2069cf7aa5ba7770d2dc9d167fab18fe09c5a8e2ae59ca256aa2361b844cDocker / Open Container Initiative (OCI) β virtual appliance (installation):
π¦ OpenCCU-3.89.11.20260919-oci_amd64.tgz (amd64/x86_64)
SHA256: 95d1d9d5d57a8973665d2d0e372aea7dd8e50f919cf76b813a2e031c5ff25239
π¦ OpenCCU-3.89.11.20260919-oci_arm64.tgz (arm64/aarch64)
SHA256: c2a7160eba67b4bf68bd01140210558b9aa8abe01374ffcf8301edb896ca44eeLXC Container β virtual appliance (installation):
π¦ OpenCCU-3.89.11.20260919-lxc_amd64.tar.xz (amd64/x86_64)
SHA256: a1e50ccebcb5daaa730b23369ec1a0132850f40874ffd4b800e95b99c6e0d857
π¦ OpenCCU-3.89.11.20260919-lxc_arm64.tar.xz (arm64/aarch64)
SHA256: fb55c2a73bd617d3ec123ecefe934b04d5783b345cde536ef19003ccd6e67190Generic-aarch64 Appliance β (ProxmoxVE):
π¦ OpenCCU-3.89.11.20260919-generic-aarch64.zip
SHA256: bc58e287840af98e8a6f44cacd476d6524daa2b508159ed6260693d2f00593cbKubernetes / K8s β virtual appliance:
see [install documentation](https://github.com/OpenCCU/OpenCCU/wiki/Installation-K…
