RutOS Security Updates: 9 CVEs Patched, Post-Quantum IPsec Arrives

Introduction
A RutOS security update is not a tedious chore but one of the most effective levers you have as a security officer: cellular routers and gateways sit at the outermost edge of the network — directly on the internet, often at sites without IT staff and not infrequently with reach into industrial systems. With the releases 7.24 (8 July 2026), 7.24.1 (20 July 2026) and 7.24.2 (13 August 2026), Teltonika has published a dense sequence of updates within a few weeks that moves quite a bit from a security perspective.
This article deliberately takes the security perspective: which CVEs were patched, which system components updated — and what is behind the post-quantum key exchange for IPsec? You will find a complete feature overview of all three releases in the series article RutOS 7.24, 7.24.1 & 7.24.2 at a glance, and the fundamentals are explained in What is RutOS?. Further articles on the brand are collected in the Teltonika blog category.
Why is router firmware hygiene security-critical?
A compromised router is rarely the end goal for attackers — it is the beachhead. Whoever takes control of the gateway at the network edge can read or redirect traffic, abuse VPN tunnels and work their way from there into internal systems. Three properties make router firmware a structurally attractive target:
- Exposed position: Routers and gateways are by definition reachable from untrusted networks — in cellular deployments often without an upstream protective layer.
- Long service lives: Industrial devices run for years, sometimes decades. Without a maintained update process, the gap to the current security baseline grows with every month.
- Little visibility: The devices sit in control cabinets, vehicles and remote sites — where no administrator drops by regularly and no endpoint agent runs.
On top of that: anyone working in regulated industries increasingly has to document patch processes and justify them to auditors. A manufacturer that discloses vulnerabilities transparently in the changelog and patches in short cycles provides the necessary foundation for that. Teltonika documents its releases publicly on the firmware pages of the manufacturer wiki — including CVE lists with severity ratings. That this maintenance runs continuously is shown by a look back: as early as RutOS 7.07 we reported here on feature and service improvements.
Which CVEs does RutOS 7.24 close?
The RutOS 7.24 feature release of 8 July 2026 closes nine CVEs, four of them with a high severity rating (score ≥ 7.0). The complete list (figures according to the Teltonika changelog):
- CVE-2026-31431 — score 7.8 (HIGH)
- CVE-2026-5720 — score 7.1 (HIGH)
- CVE-2026-40385 — score 7.1 (HIGH)
- CVE-2026-40386 — score 7.1 (HIGH)
- CVE-2026-0990 — score 5.9 (MEDIUM)
- CVE-2025-14282 — score 5.4 (MEDIUM)
- CVE-2026-0989 — score 3.7 (LOW)
- CVE-2026-4519 — score 3.3 (LOW)
- CVE-2026-0992 — score 2.9 (LOW)
The list is documented identically on the changelog pages of the RUTX50 and RUT956. We reproduce the severity ratings as Teltonika publishes them — we have not cross-checked them against the NVD. Four vulnerabilities with a score of 7.1 or higher in a single release are a clear signal: fleets still running on older firmware versions should prioritize the update — regardless of whether the release’s new features are needed.
The authoritative source for your own assessment is the changelog section of the respective device page in the Teltonika wiki, for example the RUTX50 Firmware Downloads page. Note that Teltonika maintains changelogs per device family — so check the page of your specific model.
What other system components and hardening does 7.24 bring?
Beyond the CVE patches, 7.24 updates security-relevant system components and tidies up in several places (all figures according to the RUTX50 changelog):
- dropbear 2025.89: The SSH server is brought up to a current version — for devices administered remotely, one of the most important individual components.
- SQLite 3.50.4: The embedded database is updated.
- Updated crypto defaults: The default crypto proposals for IPsec and DMVPN have been revised.
- Central certificate management: Certificates of the MQTT Modbus gateway and of Modbus over IP move into the global certificate manager — fewer scattered stores, better control over validity periods.
- Encrypted data export: Data to Server now supports SFTP and FTPS as output channels, with strict host key checking for SFTP. Telemetry and measurement data thus leave the device in encrypted form.
Security-relevant entries can also be found among the bug fixes: 2FA one-time passwords are correctly invalidated after successful authentication, the NTP client checks incoming packets for a minimum size of 48 bytes, and the IEEE 802.11r validation for unsupported encryption modes has been corrected.
The interim release 7.24.1 of 20 July 2026, by contrast, is primarily a quality and stability update — including iperf and stress-ng in the Package Manager and maintenance of the APN database. The RUTX50 changelog does not list a dedicated CVE section for 7.24.1. The release matters nonetheless: as of 28 August 2026, 7.24.1 is the firmware Teltonika lists as “Stable” — more on that in a moment.
What does RutOS 7.24.2 deliver: post-quantum IPsec and hardened authentication?
With the 7.24.2 maintenance release of 13 August 2026, Teltonika tightens the security screw further. The most striking entry: ML-KEM post-quantum key exchange for IPsec, implemented via the update of strongSwan to version 6.0.7.
Why post-quantum cryptography is already relevant today can be summed up in one phrase: “harvest now, decrypt later”. Attackers can record encrypted traffic today in order to decrypt it later, once powerful quantum computers become available. A quantum-resistant key exchange such as ML-KEM addresses exactly this scenario — the longer-lived the transmitted data, the earlier the switch pays off. That this technology is now arriving in industrial routers is remarkable: site-to-site VPNs between remote sites and headquarters are among the connections that often run unchanged for years.
In addition, 7.24.2 significantly hardens local authentication:
- PAM account lockout: After repeated failed attempts, the local account is locked — an effective bar against brute-force attacks.
- Password history: The password policy can now prevent the reuse of previous passwords.
- NTP authentication: ntpd supports authenticated time sources — relevant because a manipulated system time can undermine certificate checks and log forensics.
- Firewall connection limits: The firewall now supports per-port connection limits.
The crypto and protocol foundation is updated as well: OpenSSL 3.5.7, freeradius3 3.2.8, wireless-regdb 2026.05.30 and open62541 (OPC UA) 1.4.18. Added to this are two further CVE fixes — CVE-2026-16455 (score 6.9, MEDIUM) and CVE-2026-18368 (score 5.0, MEDIUM) — as well as a security-relevant bug fix: the SSH server previously did not listen on IPv6 addresses (figures according to the Teltonika changelog).
Beyond security, 7.24.2 also brings OSPFv3 for dynamic routing over IPv6 and the automatic creation of DHCPv6 servers for WAN interfaces — the details are in the overview article on the 7.24 series.
What does a robust patch strategy for your Teltonika fleet look like?
Teltonika runs a two-tier release model that you should use for your patch strategy. The Stable release is the firmware validated by internal QA and broad real-world deployments — currently that is 7.24.1. The Latest release — currently 7.24.2 — has been through the internal tests but, according to Teltonika, has “not yet undergone wide distribution or user validation” and may “still contain undetected issues”; the manufacturer explicitly recommends testing it “on a small number of devices first” (paraphrased from the RUTX50 firmware page).
For fleet operators, a clear procedure follows:
- Take inventory: Which device families and firmware versions are in the field? Without an up-to-date inventory, there is no sound prioritization.
- Consolidate the fleet on 7.24.1: This puts you on the Stable tier — a version that, as a point release, builds on the 7.24 feature release with its CVE patches.
- Pilot 7.24.2: A small, representative pilot group — preferably where IPsec tunnels carry long-lived data and ML-KEM delivers the greatest added value.
- Roll out centrally: For distributed fleets, rollout via Teltonika’s Remote Management System (RMS) is recommended over manual, device-by-device access.
You should plan for two limitations (as of 28 August 2026, according to the Teltonika wiki): for the RUT9xx family (including RUT951, RUT956), only 7.24 is listed so far — 7.24.1 and 7.24.2 are not yet available there. And the TAP access points (TAP100/200/400) are missing from the 7.24.2 device list. Whether and when these families will receive the point releases is not documented; the authoritative reference is the Product Firmware Updates page in the Teltonika wiki.
Practical tip: Define the pilot period in advance — say, two weeks with clear abort criteria — and specifically watch VPN stability and authentication behavior, i.e. exactly the areas 7.24.2 targets. Only then should the broad rollout follow.
Ascend distributes Teltonika and supplies hardware and RMS licenses from a single source — from device selection via the Teltonika router overview to license procurement for centralized patch management.
Conclusion
The 7.24 series shows a pattern security officers like to see: a feature release that closes nine CVEs (four of them HIGH, figures according to the Teltonika changelog), a stability update that matures into the Stable firmware shortly afterwards, and a maintenance release that hardens in a targeted way with ML-KEM post-quantum IPsec, PAM account lockout, password history and NTP authentication. Anyone who consolidates their Teltonika fleet on 7.24.1 and pilots 7.24.2 in a structured way reduces the attack surface — and sets the course early on post-quantum cryptography.
Talk to us: If you need support in assessing the updates, selecting devices or obtaining RMS licenses for centralized patch management, we are here for you. Ascend distributes Teltonika — available routers and gateways can be found on the Teltonika brand page in the Ascend Shop, and an overview of the product world on our Teltonika router page.
Frequently asked questions
Request a consultation
Unsure whether your fleet should be consolidated on 7.24.1 or already pilot 7.24.2? We assess your Teltonika environment, support your update planning and supply hardware and RMS licenses from a single source.
Matching Teltonika products at Ascend
These RutOS devices benefit directly from the 7.24.x security updates — you will find details, prices and availability on the respective product detail page in the Ascend Shop.

Teltonika RUTX11
LTE Cat 6 router with dual SIM, dual-band Wi-Fi and GNSS — available for 300,90 €.

Teltonika RUT956
Industrial 4G/LTE router with dual SIM, Ethernet, I/O, GNSS and RS485/RS232 — available for 265,44 €.

Teltonika TRB500
5G industrial gateway with Gigabit Ethernet and configurable I/O — available for 439,99 €.
Further reading
- RutOS 7.24, 7.24.1 & 7.24.2: all firmware updates at a glance
- What is RutOS? The Teltonika operating system explained
- Teltonika TSF010: VDC-only order codes are being phased out
- Teltonika routers at Ascend
- Teltonika blog category
- Looking back: RutOS 7.07 — optimizing network services
- Security features of the RUT301 and RUT361 routers
- Teltonika brand page in the Ascend Shop
This article was researched and written with AI support and reviewed by Ascend before publication.
Ready for your next project?
Talk to our team about your requirements.
Related posts

What Is RutOS? The Teltonika Operating System Clearly Explained
RutOS is the operating system of Teltonika’s routers and gateways. We explain device families, the Stable/Latest model, security maintenance and the feature set of version 7.24.

Teltonika TSF010: VDC-only Order Codes End on 1 October 2026 — What Buyers Need to Know
PCN of 7 August 2026: Teltonika discontinues the TSF010’s VDC-only order codes on 1 October 2026. What this means for procurement, BOMs and ongoing projects.

RutOS 7.24, 7.24.1 & 7.24.2: All Teltonika Firmware Updates at a Glance
RutOS 7.24, 7.24.1 and 7.24.2 at a glance: release chronology, feature highlights, device matrix, Stable vs. Latest tier and a clear update recommendation for your fleet.





