Release Date:
August 13, 2026
Enhancements:
- Support for the following new AV profiles:
- Turtle Profile
- Just Add Power
- Updates for the following existing AV profiles:
- Sonos: Updated profile configurations
- AVoIP Lightware: Updated profile configurations
- Audio-Technica: Updated default profile color
- Audio AES67: Updated profile descriptions
- Nice Home Management: Updated profile name to Elan OS
- Lighting: Updated profile description
- Addition of Non-Unicast Global Hash Mode settings under Configure > Link Aggregation
- Addition of the Timeout column to the multicast table
- Addition of REST API support for L2/L3 multicast, PTP BC/TC, and port mirroring
- Support for configurable RSTP Hello timer [CE-7584]
- Upgrade to the underlying SDK and kernel versions, resulting in changes to the following features:
- DSA keys are removed from SSH for security reasons.
- The command format aaa ias-user username <username> is changed to aaa ias-user username <username> dot1x.
Bug Fixes:
- Fixes the issue where VLAN participation cannot change when auto-trunk is present. (CESMB-7771)
- Fixes the issue where changing a DHCP scope in the AV UI does not delete or update the first exception from the initial scope. (CESMB-7915)
- Fixes the issue where third-party switches win the multicast querier election even when an ACL is applied to block multicast traffic on the uplink port. [CE-6990]
- Fixes the issue where a backed-up startup configuration file fails to import. [CE-7073]
- Fixes the issue where the documentation links under Help > Online Help > Support and User Guide do not work. [MS-5481]
- Fixes the issue where multicast SSDP packets do not flood after the configuration is cleared. [MS-5492]
- Fixes the issue where the switch does not assign an IP address through DHCP. [CE-7335]
- Fixes the issue where the switch sends EAP packets on link-up. [CE-7391]
- Fixes the issue where the CLI output for the show ip pim statistics command is misaligned. [CE-7569]
- Fixes the issue where bandwidth does not display in the AV UI port overview. [CE-7604]
- Fixes the issue where a port's PVID is not reported in the VLAN membership when the port is not a member of the PVID VLAN. (PRJCBUGEN-62243)
- Fixes the issue where excluding a port from a VLAN through Insight set the port to Forbidden on that VLAN instead of removing its membership. (PRJCBUGEN-61052)
- Fixes the issue where launching the switch device UI from Insight does not honour the configured HTTPS management port and redirects to an invalid port. (PRJCBUGEN-60188)
- Fixes the issue where an auto-trunk port changes to a static trunk after device restart and onboarding to Insight, which prevents auto-trunk from working on that port. (PRJCBUGEN-62629)
- Fixes the issue where Insight reports the switch IP address as 0.0.0.0 when a non-default VLAN is used for management. (PRJCBUGEN-61109)
AV UI Known Issues:
- After a configuration clear, the original VLAN 1 profile lingers for up to 1 minute on first login. All configurations are cleared and there is no functional impact.
- If a PoE schedule is applied to the same port multiple times, only the most recent schedule takes effect. The device UI might display a conflicting schedule as active, but this status is not valid.
- gPTP Clock Master Causes Time Drift with AVB MILAN Devices:
If the switch becomes the gPTP clock master, time drift issues might occur when AVB MILAN devices are in use.
Workaround: When creating an "Audio Video AVB MILAN" profile in AVUI, set the Local Clock Priority 1 and Priority 2 values to 255 to prevent the switch from acting as the clock master.
- Stale Spanning Tree Configuration After Firmware Upgrade from AVUI 2.2.13.29:
When upgrading firmware from AVUI 2.2.13.29 to the current release, access port configurations with no spanning-tree port mode may persist. If Dante devices are connected using redundancy ports, this can cause a network loop.
Workaround: Manually clear the stale configuration by setting the affected interfaces back to spanning-tree port mode.
- Kramer AV Single-VLAN Profile Cannot Be Modified When Using VLAN 1:
If a Kramer AV profile is created with a single VLAN and that VLAN is VLAN 1, the profile cannot be modified to another single-VLAN profile.
Workaround: Use a VLAN ID other than VLAN 1 when creating a single-VLAN Kramer AV profile.
Firmware Known Issues:
-
This firmware includes a configuration migration process that transitions the default web browser protocol from HTTP to HTTPS. When you upgrade to this firmware and import an older configuration with HTTPS disabled, HTTPS becomes enabled.
Workaround: Reconfigure the web browser protocol settings manually after you perform a firmware upgrade or import an older configuration.
- During your initial log in, you must set up a password to access the switch. However, if you access the main UI before you set up a password and simultaneously set the password in the AV UI, the switch console might lock for up to 15 minutes.
Workaround: Configure a password in either the main UI or the AV UI to avoid this lock up issue.
-
Workaround:Ensure both the private key and certificate are fully uploaded before you enable HTTPS. If the issue still occurs, remove the incomplete HTTPS-related private key or certificate, and disable HTTPS before reconfiguring.
- For up to 20 minutes after a factory reset, CPU utilization runs at full load while the SSL key is being generated. Workaround: wait ~20 minutes — CPU utilization returns to normal once key generation completes.
Warnings:
Read and follow these warnings before updating your firmware:
- SNTP is deprecated from firmware version 13.0.5.10 onwards and NTP is introduced. Configure an NTP server in your network. Remove SNTP related settings from the configuration file on firmware version 13.0.4.x before you apply it to the switch running firmware version 13.0.5.x.
- HTTPS is set to the default web browser protocol from firmware version 13.0.5.20 and newer versions. The default certificate is self-signed, so you might encounter a browser warning when you log in. To avoid this warning, you can download your own certificate issued by a trusted Certificate Authority (CA).
General Information:
- The boot code remains at the existing version 1.0.0.11 in this switch firmware.
- The process of upgrading the firmware and boot code takes about three minutes. Apply the “update bootcode” command from the command line interface. Do not switch off or restart the device during the upgrade process.
- AppMgr is upgraded to version 1.0.6.16 in this switch firmware.
- Insight and Engage/AV UI are mutually exclusive. This means you can only use one of these options to configure and manage the switch, not both.
- If the encrypted password in the configuration file does not adhere to the NETGEAR password policy, when the configuration file is loaded on the firmware version 13.0.5.16 or later, you must create a new password during the initial login.
Download Link: https://www.downloads.netgear.com/files/GDC/M4250/GSM421xxx_MSM4214_XSM4216F_V13.0.6.7.zip
Firmware Update Instructions:
To update your product’s firmware, follow the instructions in your product’s user manual. To find your user manual, visit https://www.netgear.com/support/, enter your model number in the search box, and click the Documentation button on the product page.