What is the Kali Linux 2025 Nexmon update for Raspberry Pi Wi-Fi, and how does it enable monitor mode and packet injection without a USB dongle?

Kali Linux's 2025 update introduces two powerful Nexmon-based packages — brcmfmac-nexmon-dkms and firmware-nexmon — that allow Raspberry Pi users to unlock monitor mode and packet injection using only the onboard Wi-Fi. This groundbreaking update eliminates the need for external USB Wi-Fi dongles, especially on models like Raspberry Pi 4, 5, and Zero W. Built on Nexmon’s firmware patching framework, this update turns Raspberry Pi into a fully capable wireless penetration testing device. It is now easier than ever to set up portable hacking labs or perform Wi-Fi auditing directly on ARM devices. Compatible with kernel 6.12+, it marks a significant shift in mobile ethical hacking capabilities.

Jul 23, 2025 - 14:23
Updated: 8 days ago
111.9k
What is the Kali Linux 2025 Nexmon update for Raspberry Pi Wi-Fi, and how does it enable monitor mode and packet injection without a USB dongle?

Quick answer: Nexmon is a firmware-patching framework for Broadcom and Cypress Wi-Fi chips, made by the SEEMOO lab at TU Darmstadt. It lets a Raspberry Pi's built-in Wi-Fi run in monitor mode, and on some chips inject frames, which the stock driver cannot do. Kali ships the Nexmon driver as a DKMS package so it survives kernel updates. Whether your board also supports injection depends on its exact chip, so always check the current Kali release notes and the Nexmon support list. Use it only on networks you own or are authorised to test.

Key takeaways

  • Nexmon patches Broadcom and Cypress Wi-Fi firmware, enabling monitor mode on the Pi's built-in chip, which the stock driver cannot do.
  • Injection support depends on your exact Raspberry Pi chip, so check the Kali release notes and Nexmon support list first.
  • Kali ships the driver as a DKMS package so it survives kernel updates, but a USB adapter remains the more reliable choice for injection.

Authorised testing only. Monitor mode and frame injection let you capture and send raw Wi-Fi frames. Using them against networks you do not own or have written permission to test can breach India's Information Technology Act, 2000. Build a lab with your own access point and test only there.

What is Nexmon, and what does it do?

Nexmon patches the closed-source firmware on Broadcom and Cypress Wi-Fi chips so the chip can do things the vendor driver does not expose. The two capabilities that matter for wireless security work are monitor mode (listening to all Wi-Fi frames in range, not just those addressed to you) and frame injection (sending crafted frames). It is a research project from the SEEMOO lab at TU Darmstadt, not a Kali original.

The point of the Kali integration is that the Raspberry Pi's onboard Wi-Fi can be used for these tasks, so a small, battery-friendly board can serve as a portable Wi-Fi testing platform without a separate adapter on every job.

What has Kali actually shipped for the Raspberry Pi?

Treat marketing-style claims carefully and check the release notes for your version. The confirmed position from Kali's 2025 Raspberry Pi work is:

  • The Nexmon kernel module is packaged as brcmfmac-nexmon-dkms. Because it is a DKMS package, the driver rebuilds automatically when the kernel updates, so you do not recompile by hand.
  • The Nexmon firmware is a separate piece from the driver, and its availability has been rolled out progressively rather than all at once. A working setup needs both the patched driver and compatible firmware for your board's chip.
  • Kali's Raspberry Pi kernels in that cycle were based on the Raspberry Pi OS 6.6 kernel series, not a single fixed later version. Confirm the exact kernel your image ships with using uname -r.

Because the details change between releases, the authoritative source is the official Kali release notes for the version you are installing.

Which Raspberry Pi models are supported?

Monitor mode is supported more widely than injection. According to the Nexmon project, the models with monitor mode and injection support are the Raspberry Pi 3, 3+, 4, Zero W and Zero 2 W, which use chips such as the bcm43430 and bcm43455 family. Support is per chip, so a given feature may work on one board and not another, and newer boards can use different chips that have only partial support.

CapabilityReality
Monitor modeSupported on most listed Pi models with Nexmon
Frame injectionDepends on the exact Wi-Fi chip; not guaranteed on every board
Band supportVaries by model; some support 2.4 GHz and 5 GHz, others 2.4 GHz only

Before you rely on a board for a task, confirm its chip against the support matrix in the Nexmon project repository.

How do you set it up on Kali?

Start from an up-to-date Kali ARM image for your board. The general flow is to update the system and install the Nexmon driver package:

sudo apt update
sudo apt full-upgrade -y
sudo apt install -y brcmfmac-nexmon-dkms
sudo reboot

After rebooting, check whether your interface can enter monitor mode with iw dev and iw phy, which report the modes the hardware supports. If your Kali version also packages the matching firmware, install it as the release notes direct. If the combination is not yet available for your chip, a supported external USB adapter remains the reliable option.

A common mistake is assuming the driver alone is enough. The driver and the firmware work together, so a monitor-mode failure after installing only the DKMS package usually means the firmware side is missing for your board.

Why monitor mode and injection matter

These capabilities are the basis of legitimate wireless security work: capturing traffic to study protocols, auditing the strength of your own Wi-Fi, and testing how an access point you control responds to unusual frames. They also underpin attacks such as deauthentication, which is exactly why defenders need to understand them. On the defensive side, a wireless intrusion detection system watches for the same injected management frames, and modern Wi-Fi (WPA3 and protected management frames) is designed to blunt deauthentication. Learning both sides makes the knowledge useful rather than just offensive.

Onboard Nexmon or a USB adapter?

Each has a place. Onboard Nexmon is free and keeps your rig compact, which suits a portable lab or a classroom set of Pis. A dedicated USB adapter with a well-supported chipset tends to be more reliable for sustained capture and injection, supports more bands and antennas, and is easy to move between machines. For learning and light testing on a supported board, onboard Wi-Fi is convenient; for heavier or more dependable work, keep a known-good USB adapter.

Where to go next

Set up a lab with your own router, confirm your board's chip and capabilities, and practise capture before you touch injection. To build the surrounding skills, see our guide to the top ethical hacking tools in Kali Linux and the top Kali Linux tools overview. For a structured, lab-based route into wireless and network security testing, the ethical hacking and cyber security course provides authorised targets to practise on.

Related reading

Frequently Asked Questions

Nexmon is a firmware-patching framework for Broadcom and Cypress Wi-Fi chips, developed by the SEEMOO lab at TU Darmstadt. It exposes capabilities such as monitor mode and, on some chips, frame injection that the stock vendor driver does not provide.

It installs the Nexmon-patched Wi-Fi driver as a DKMS module, so the driver rebuilds automatically every time the kernel updates. It is the driver half of the setup; a matching patched firmware for your board's chip is also needed for the advanced modes to work.

On supported boards with the Nexmon driver and compatible firmware, the onboard Wi-Fi can enter monitor mode. Injection is less widely supported and depends on the exact chip. Check your Kali release notes and the Nexmon support list before relying on it.

The Nexmon project lists the Raspberry Pi 3, 3+, 4, Zero W and Zero 2 W for monitor mode and injection, using chips such as the bcm43430 and bcm43455 family. Support is per chip, so always confirm your specific board against the project's matrix.

No. Injection support is tied to the specific Wi-Fi chip, so some boards support monitor mode but not reliable injection. Confirm your board's chip in the Nexmon repository rather than assuming all models behave the same.

Kali's Raspberry Pi kernels in the 2025 cycle were based on the Raspberry Pi OS 6.6 kernel series. The exact version changes between releases, so check with uname -r on your own system and follow the current Kali release notes.

No. The driver ships as a DKMS package, which rebuilds the module automatically on each kernel update. You install the package and reboot rather than compiling anything by hand.

It depends. Onboard Nexmon is free and keeps the setup compact, which suits portable or classroom labs. A well-supported USB adapter is usually more reliable for sustained capture and injection and supports more bands, so many testers keep one as a dependable backup.

Only on networks you own or have written authorisation to test. Capturing or injecting frames on other people's networks can breach India's Information Technology Act, 2000. Set up your own access point in a lab and practise there.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.