What is the Kali Linux 2025 Nexmon update for Raspberry Pi Wi-Fi, and how does it enable monitor mode and packet injection without a USB dongle?
Kali Linux's 2025 update introduces two powerful Nexmon-based packages — brcmfmac-nexmon-dkms and firmware-nexmon — that allow Raspberry Pi users to unlock monitor mode and packet injection using only the onboard Wi-Fi. This groundbreaking update eliminates the need for external USB Wi-Fi dongles, especially on models like Raspberry Pi 4, 5, and Zero W. Built on Nexmon’s firmware patching framework, this update turns Raspberry Pi into a fully capable wireless penetration testing device. It is now easier than ever to set up portable hacking labs or perform Wi-Fi auditing directly on ARM devices. Compatible with kernel 6.12+, it marks a significant shift in mobile ethical hacking capabilities.
Quick answer: Nexmon is a firmware-patching framework for Broadcom and Cypress Wi-Fi chips, made by the SEEMOO lab at TU Darmstadt. It lets a Raspberry Pi's built-in Wi-Fi run in monitor mode, and on some chips inject frames, which the stock driver cannot do. Kali ships the Nexmon driver as a DKMS package so it survives kernel updates. Whether your board also supports injection depends on its exact chip, so always check the current Kali release notes and the Nexmon support list. Use it only on networks you own or are authorised to test.
Key takeaways
- Nexmon patches Broadcom and Cypress Wi-Fi firmware, enabling monitor mode on the Pi's built-in chip, which the stock driver cannot do.
- Injection support depends on your exact Raspberry Pi chip, so check the Kali release notes and Nexmon support list first.
- Kali ships the driver as a DKMS package so it survives kernel updates, but a USB adapter remains the more reliable choice for injection.
Authorised testing only. Monitor mode and frame injection let you capture and send raw Wi-Fi frames. Using them against networks you do not own or have written permission to test can breach India's Information Technology Act, 2000. Build a lab with your own access point and test only there.
What is Nexmon, and what does it do?
Nexmon patches the closed-source firmware on Broadcom and Cypress Wi-Fi chips so the chip can do things the vendor driver does not expose. The two capabilities that matter for wireless security work are monitor mode (listening to all Wi-Fi frames in range, not just those addressed to you) and frame injection (sending crafted frames). It is a research project from the SEEMOO lab at TU Darmstadt, not a Kali original.
The point of the Kali integration is that the Raspberry Pi's onboard Wi-Fi can be used for these tasks, so a small, battery-friendly board can serve as a portable Wi-Fi testing platform without a separate adapter on every job.
What has Kali actually shipped for the Raspberry Pi?
Treat marketing-style claims carefully and check the release notes for your version. The confirmed position from Kali's 2025 Raspberry Pi work is:
- The Nexmon kernel module is packaged as
brcmfmac-nexmon-dkms. Because it is a DKMS package, the driver rebuilds automatically when the kernel updates, so you do not recompile by hand. - The Nexmon firmware is a separate piece from the driver, and its availability has been rolled out progressively rather than all at once. A working setup needs both the patched driver and compatible firmware for your board's chip.
- Kali's Raspberry Pi kernels in that cycle were based on the Raspberry Pi OS 6.6 kernel series, not a single fixed later version. Confirm the exact kernel your image ships with using
uname -r.
Because the details change between releases, the authoritative source is the official Kali release notes for the version you are installing.
Which Raspberry Pi models are supported?
Monitor mode is supported more widely than injection. According to the Nexmon project, the models with monitor mode and injection support are the Raspberry Pi 3, 3+, 4, Zero W and Zero 2 W, which use chips such as the bcm43430 and bcm43455 family. Support is per chip, so a given feature may work on one board and not another, and newer boards can use different chips that have only partial support.
| Capability | Reality |
|---|---|
| Monitor mode | Supported on most listed Pi models with Nexmon |
| Frame injection | Depends on the exact Wi-Fi chip; not guaranteed on every board |
| Band support | Varies by model; some support 2.4 GHz and 5 GHz, others 2.4 GHz only |
Before you rely on a board for a task, confirm its chip against the support matrix in the Nexmon project repository.
How do you set it up on Kali?
Start from an up-to-date Kali ARM image for your board. The general flow is to update the system and install the Nexmon driver package:
sudo apt update
sudo apt full-upgrade -y
sudo apt install -y brcmfmac-nexmon-dkms
sudo reboot
After rebooting, check whether your interface can enter monitor mode with iw dev and iw phy, which report the modes the hardware supports. If your Kali version also packages the matching firmware, install it as the release notes direct. If the combination is not yet available for your chip, a supported external USB adapter remains the reliable option.
A common mistake is assuming the driver alone is enough. The driver and the firmware work together, so a monitor-mode failure after installing only the DKMS package usually means the firmware side is missing for your board.
Why monitor mode and injection matter
These capabilities are the basis of legitimate wireless security work: capturing traffic to study protocols, auditing the strength of your own Wi-Fi, and testing how an access point you control responds to unusual frames. They also underpin attacks such as deauthentication, which is exactly why defenders need to understand them. On the defensive side, a wireless intrusion detection system watches for the same injected management frames, and modern Wi-Fi (WPA3 and protected management frames) is designed to blunt deauthentication. Learning both sides makes the knowledge useful rather than just offensive.
Onboard Nexmon or a USB adapter?
Each has a place. Onboard Nexmon is free and keeps your rig compact, which suits a portable lab or a classroom set of Pis. A dedicated USB adapter with a well-supported chipset tends to be more reliable for sustained capture and injection, supports more bands and antennas, and is easy to move between machines. For learning and light testing on a supported board, onboard Wi-Fi is convenient; for heavier or more dependable work, keep a known-good USB adapter.
Where to go next
Set up a lab with your own router, confirm your board's chip and capabilities, and practise capture before you touch injection. To build the surrounding skills, see our guide to the top ethical hacking tools in Kali Linux and the top Kali Linux tools overview. For a structured, lab-based route into wireless and network security testing, the ethical hacking and cyber security course provides authorised targets to practise on.
Related reading
- Understanding VMware Network Adapters | Bridged, NAT, Host-Only, and Custom Networks with Real-World Examples
- What Is the Role of the Linux Kernel in Kali Linux? The Complete Guide
- What is Raspberry Pi Used For, How to Use It, and Real-Time Examples for Programming and Ethical Hacking | Raspberry Pi Explained
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0