RUTC42 Firmware Downloads
This page contains firmware files for RUTC42 devices. Look to the table below or the changelog to find download links.
Stable firmware - this version has been tested through both internal QA processes and large-scale user deployments. All known issues have been resolved based on user reports and testing feedback. Stable firmware is currently used as the default for updates and is also deployed in mass production. To upgrade firmware using WebUI, follow the instructions in RUTC42 Firmware.
Latest firmware - this is the most recent firmware release, featuring the latest updates, features, and fixes. While it has passed internal testing, it has not yet undergone widespread deployment or user validation. It may still contain undiscovered issues. We recommend testing on a small number of devices before considering broader updates.
Note: packages for Package Manager are independent from firmware and can be downloaded in the Package Downloads page.
| File | Type | Release date | Size | MD5 | Links |
|---|---|---|---|---|---|
| RUTC_R_00.07.24.1_WEBUI.bin | Stable FW |
2026.07.20 | 29 MB | 39123f1572fa0a120a91a2af90807657 | Changelog API |
| RUTC_R_00.07.24.1_WEBUI.bin | Latest FW |
2026.07.20 | 29 MB | 39123f1572fa0a120a91a2af90807657 | Changelog API |
| RUTC_R_SDK_00.07.24.1.tar.gz | SDK | 2026.07.20 | 75 MB | ab4927159687a90dc1453d3b50dcc568 |
FW checksums
Checksums for firmware files can be found here.
Changelog
RUTC_R_00.07.24.1 | 2026.07.20
- New
- Network
- Iperf: added iperf to Package Manager
- Mobile: added "internet.telenor.se" APN for operator "Telenor" into APN database
- Mobile: added "services.telenor.se" APN for operator "Telenor" into APN database
- Mobile: added "comgate.m2m" APN for operator "KPN" into APN databse
- Services
- Stress-ng: added stress-ng to Package Manager
- Network
- Improvements
- Network
- Mobile: increased "iot.t-mobile.com" APN priority for T-Mobile operator with 311-882 MCC-MNC
- System
- Integrity: improved the time it takes to generate integrity database on first boot
- Network
- Fix
- Network
- Wireless: fixed received ieee80211 action frame forwarding in station mode
- Services
- Event juggler: fixed SMS sending failures when messages are sent in rapid succession
- System
- Troubleshoot: fixed logs from flash inclusion
- Network
RUTC_R_00.07.24 | 2026.07.08
- New
- Network
- Mobile: added "soracom.io" APN for "NTT Docomo" and "KDDI" operators to the APN database
- Mobile: added "internet" APN for "Bite" operator to APN database
- Network
- Improvements
- Network
- Dynamic routes: removed redundant interfaces from dropdown
- Dynamic routes: moved instance naming into edit modals for OSPF
- Firewall: increased maximum allowed length for "extra" field in traffic rules to 256 characters
- Internet Status: refactored the web page to leverage caching, improving responsiveness
- Mobile: updated blocklist and allowlist operator selection modes to use the lists in the user-defined order
- Mobile: added "Ignore Home Operator Priority" toggle for blocklist and allowlist network selection modes
- Mobile: added APN priority control for mobile operator
- Mobile: added ICCID display when SIM card is inserted but not yet unlocked with PIN
- Realtime Traffic: improved ubus method input validation
- Static Routes: added default table for IPv4 static routes in API
- Wireless: added RSSI to hostapd log
- mt76: updated version to 2025-02-14
- Services
- Data to Server: added SFTP and FTPS support for FTP output
- Data to Server: added SFTP strict host key checking support for FTP output
- Data to Server: added name and MAC code for MQTT topic wildcards
- DMVPN: updated default ipsec crypto proposal
- DNP3 Client: added IP address and port filtering options for database API requests
- Event juggler: added name, serial code, MAC code for MQTT topic wildcards
- IEC 60870-5 Client: added configuration support for app layer, link layer and APCI parameters
- IEC 60870-5 Server: added new time_tag option in for server_instance, information object data types support with time_tag value
- IEC 60870-5 Server: added new information object data types (time tag variants) for information object tags
- IEC 60870-5 Server: added configuration support for app layer, link layer and APCI parameters
- IPsec: updated default crypto proposal
- Modbus Client: added IP address filtering options for database API requests
- Modbus Client: added constants for MAC, serial and device name in the alarm MQTT action topic
- MQTT Modbus Gateway: added certificates to global certificate manager
- Over IP: added certificates to global certificate manager
- Over IP: added serial inactivity timeout option
- SMS Forwarding: added authentication retries for sender email account
- SNMP: added download icon for the MIB file download button
- SNMP: set default system name to represent the same value as device's hostname
- Tinc: updated interface and host settings to support custom dynamic names
- Tinc: updated port management to ensure only active instances occupy network ports
- TR-069: added parameter name and parameter value validation when calling "SetParameterValues" command
- TR-069: added Device.IP.Diagnostics.TraceRoute object based on "TR-181 Issue 2 Amendment 20", with implementation-specific deviations
- TR-069: improved Device.WiFi.SSID object based on "TR-181 Issue 2 Amendment 20", with implementation-specific deviations
- TR-069: improved Device.WiFi.Radio object based on "TR-181 Issue 2 Amendment 20", with implementation-specific deviations
- TR-069: improved TR-069 connection initiation speed to the ACS
- Traffic Logging: added SFTP strict host key checking support for FTP uploads
- Wake on LAN: added bulk action for delete and wake device
- System
- 2FA: improved log messages
- Backup: added backup generation type selection
- dropbear: updated version to 2025.89
- SQLite3: updated version to 3.50.4
- Network
- Fix
- Network
- Devices: fixed validation when applying backup
- DHCP server: fixed DHCP server lease time range validation
- DHCP server: fixed IPv4 Static Leases page crash when mobile interface is disabled
- DHCP server: fixed missing validation for passthrough mode IP address in IPv4 Static Leases
- DHCP server: fixed IP range validation for disabled IPv4 server
- Dynamic routes: fixed multiple "OSPF" issues related to labels, help texts and placeholders
- Dynamic routes: fixed "NBMA" help text
- Dynamic routes: fixed config generation for multiple networks, redistribution options and IPv4 setups when using allow VPN
- Dynamic routes: fixed NHRP validation errors during backup upload
- Firewall: fixed traffic rules with TCPMSS target creation
- Firewall: fixed low TCP throughput when software flow offloading is used over certain interfaces
- Firewall: fixed zones backup applying for "in" and "out" API options
- Mobile: fixed SIM switch "On data connection fail" rule triggering unexpectedly when no SIM card is inserted
- Network: fixed incorrect bridge ports show for interface
- Ports Settings: fixed "advert" option validation in API
- VLAN: fixed multiple POST request for /port_based_vlan/config/
- Wireless: added IEEE 802.11r validation for unsupported encryption modes
- Services
- Cloud of Things: fixed firmware reading from the file
- DLMS: fixed incorrect translations
- DLMS: fixed missing field validation for DLMS COSEM values and DLMS COSEM groups
- DMVPN: fixed endpoint to return correct remote IP address
- DNP3 Client: fixed validations for API database queries
- DNP3 Outstation: fixed deadlock occurring when reading objects defined from data sources
- EoIP: fixed backup to work correctly
- Event juggler: fixed static IO name mapping
- Event juggler: fixed GSM events to send a message for all newly matched ranges, instead of only the first one that matched
- Hotspot: fixed Hotspot interfaces to be ignored in DHCP config
- IEC 60870-5 Client: fixed test and scan request body validation
- IEC 60870-5 Client: fixed device validation
- IEC 60870-5 Client: fixed inconsistent server address requirement checks
- IEC 60870-5 Client: fixed required field validation when feature is disabled, added inline serial device hint in serial device configuration modal
- IEC 60870-5 Client: fixed excessive logging on database query API requests
- IEC 60870-5 Client: fixed validations for API database queries
- IEC 60870-5 Client: fixed information object value parsing when using different IO types
- IEC 60870-5 Client: fixed default timeout t0 and max ASDU size definitions
- IEC 60870-5 Server: fixed required field validation when feature is disabled
- IEC 60870-5 Server: fixed error when time_tag option was omitted
- IEC 60870-5 Server: fixed information object issue where multiple string values could not be used
- IEC 60870-5 Server: fixed incorrect seconds parsing for time tag
- IEC 60870-5 Server: fixed default timeout t0 and max ASDU size definitions
- Impulse Counter: fixed I/O input validation errors during backup upload
- IPsec: fixed remote endpoints using FQDNs
- Modbus Client: fixed incorrect Modbus client data source 64bit value calculation
- Modbus Client: fixed I/O input validation errors during backup upload
- Modbus Server: fixed data source issue where reading out of data source range was allowed
- Modbus TCP over Serial Gateway: fixed single ID option not working
- MQTT Modbus Gateway: fixed TLS certificates read permission issue
- MQTT Modbus Gateway: fixed application crash on restart
- OPC UA Server: fixed service port issue causing the port to always be set to 4840
- OpenConnect: fixed status endpoint
- OpenConnect: fixed service not starting after reboot
- OpenConnect: fixed validation errors when uploading backup
- OSPF: fixed name overwriting and validation errors during backup upload
- Over IP: fixed close connections feature for client and server modes
- RMS: fixed 'rms_status' rule response when the RMS service is disabled
- SMS Utilities: fixed response message
- SMS Utilities: fixed SIM switch functionality
- SMS Utilities: fixed OpenVPN instance validation before enabling it
- SMS Utilities: fixed WebUI is not accessible via public IP after SMS "webon" command
- SMS Utilities: fixed device is not accessible via public IP over ssh after SMS "sshon" command
- SMS Utilities: fixed not updating SSH package local access and ssh wan access configuration parameters after "sshon"/"sshoff" commands
- SMS Utilities: fixed not updating HTTP package local access configuration parameters after "webon"/"weboff" commands
- SNMP: fixed minor webui validation bug
- UPnP: fixed model, serial and uuid field validations
- Zerotier: fixed backup to work correctly
- System
- 2FA: fixed OTP code invalidation after successful authentication
- 2FA: fixed issues with symbols in usernames
- API Core: fixed endpoints added through SDK not being loaded
- Auto Reboot: fixed sending ping/wget SMS from chosen modem
- Backup: fixed uploading older backups with storage memory expansion enabled
- NTP Client: fixed NTP packet size check to verify that received packet size is at least 48 bytes (standard NTP packet size without optional fields)
- NTP Client: fixed time sync, when there is no mobile connection
- Site Manager: fixed keepalive issue where unpaired devices would disappear
- Site Manager: fixed sync issue where devices would get stuck after pairing
- Update Firmware: fixed keep-settings behavior for SDK when read-only filesystem is disabled
- Network
- CVE Patches
- CVE-2026-0989 - 3.7 (LOW)
- CVE-2026-0990 - 5.9 (MEDIUM)
- CVE-2026-0992 - 2.9 (LOW)
- CVE-2026-4519 - 3.3 (LOW)
- CVE-2026-5720 - 7.1 (HIGH)
- CVE-2026-31431 - 7.8 (HIGH)
- CVE-2026-40385 - 7.1 (HIGH)
- CVE-2026-40386 - 7.1 (HIGH)
RUTC_R_00.07.23.7 | 2026.06.26
- Improvements
- System
- openssl: updated version to 3.0.21
- System
- Fix
- Network
- Mobile: fixed 'Status -> Mobile' page to correctly display band and carrier aggregation information
- System
- API Core: fixed regression which didn't allow saving options with unicode characters
- Network
RUTC_R_00.07.23.6 | 2026.06.15
- Improvements
- System
- Backup: restored backup generation to backup without API
- System
RUTC_R_00.07.23.5 | 2026.06.09
- Fix
- Network
- Mobile: fixed application segmentation fault with low signal reconnect enabled
- System
- Backup: fixed backup generation for child endpoints
- Network
RUTC_R_00.07.23.4 | 2026.05.29
- CVE Patches
- CVE-2026-2291 - 7.3 (HIGH)
- CVE-2026-4890 - 7.5 (HIGH)
- CVE-2026-4891 - 5.3 (MEDIUM)
- CVE-2026-4892 - 8.4 (HIGH)
- CVE-2026-4893 - 5.3 (MEDIUM)
- CVE-2026-5172 - 7.3 (HIGH)
RUTC_R_00.07.23.3 | 2026.05.21
- Fix
- Network
- Network: fixed validation error when changing interface devices and enabling WAN to LAN at the same time
- Network
- CVE Patches
- CVE-2026-8914 - 8.5 (HIGH)
RUTC_R_00.07.23.2 | 2026.05.18
- Fix
- Network
- Network: fixed interface and DHCP desynchronization after interface name change
- Services
- IPsec: fixed xauth not working in certain conditions
- Network
- CVE Patches
- CVE-2026-31431 - 7.8 (HIGH)
RUTC_R_00.07.23.1 | 2026.05.05
- Fix
- Network
- QOS: fixed incorrect QoS being applied to interfaces after changing interface metric
- Network
RUTC_R_00.07.23 | 2026.04.24
- New
- Network
- Mobile: added "iot.melita.io" APN for operator "Melita" into APN database
- Mobile: added "web.melita" APN for operator "Melita" into APN database
- Network: added DS-lite protocol support
- Services
- TR-069: added Device.Ethernet.Interface object based on "TR-181 Issue 2 Amendment 20", with implementation-specific deviations
- TR-069: added Device.Hosts.Host object based on "TR-181 Issue 2 Amendment 20", with implementation-specific deviations
- TR-069: added Device.NAT.PortMapping object based on "TR-181 Issue 2 Amendment 20", with implementation-specific deviations
- System
- Kernel: enabled Multipath TCP (MPTCP) support in the kernel configuration
- SSH: added 2FA support
- WebUI: added 2FA support
- WebUI: added dark theme
- Network
- Improvements
- Network
- Firewall: improved NAT offloading validation message in API
- Network usage: improved "Total usage" data deletion funcionality
- Realtime Traffic: improved performance when switching between time periods
- Static Routes: added an enable switch to allow disabling routes
- Wireless: added the ability to kick and block clients from the Status -> Wireless -> Interfaces page
- Wireless: added disconnect reason to hostapd log
- cURL: updated version to 8.19.0
- Services
- Data to Server: added wildcard for mqtt topics
- DMVPN: updated "Lifetime" and "IKE lifetime" fields and validations
- Event juggler: added "Signal quality" event
- I/O Status: added a switch component to the I/O Status table State column for state configuration
- IPsec: added warning messages for insecure proposal options
- Modbus Client: increased connection delay limits to 10s (10000ms)
- Modbus TCP over Serial Gateway: added configurable inter-frame timeout for serial communication
- SNMP: improved GSM signal strength trap with condition 'Less than', 'More than' and 'Range' triggers
- SNMP: removed Events log signal strength trap - GSM signal strength trap should be used instead
- SSTP: added connection status monitoring
- TR-069: improved Device.WiFi.AccessPoint object based on "TR-181 Issue 2 Amendment 20", with implementation-specific deviations
- TR-069: updated secure connection hint to inform that TLS works only when HTTPS is used
- Net-SNMP: updated version to 5.9.5.2
- System
- API Core: replaced Lua 5.1 with LuaJIT 2.1
- Auto Reboot: updated abbreviated month and day names to full names for improved translation support
- System Users: improved validation to allow usernames starting with numbers
- Kernel: updated version to 6.6.126
- Network
- Fix
- Network
- Mobile: fixed a rare mobile application crash case when changing APN
- MPLS: fixed package re-installation after updating with keep settings
- Network: fixed protocol validation for LAN interfaces in API
- Network: fixed interface deletion when page is not fully loaded
- Network: fixed firewall zone select not showing VPN networks in LAN and WAN pages
- Ports Settings: fixed being able to choose different link duplex mode when hardware doesn't allow
- QOS: fixed connectivity issues when QoS is enabled
- QOS: fixed an issue where settings were not correctly applied after saving
- Realtime Traffic: fixed multiple plot rendering bugs related to daylight saving transitions
- Wireless: fixed hostapd "no buffer space available" error with multiple SSIDs
- Wireless: fixed SSID deletion when page is not fully loaded
- Wireless: fixed DFS state handling after CAC end
- Services
- Data to Server: fixed button positioning on smaller screens in configuration creation modal
- Data to Server: fixed a rare case where stale data was sent via FTP after configuration changes
- Data to Server: fixed FTP upload when the selected directory doesn't exist - now it is created if the FTP server allows it
- DLMS: fixed database error in the API endpoint for database entries
- DNP3 Client: fixed database error in the API endpoint for database entries
- Email to SMS: fixed process hang in some rare cases
- Hotspot: fixed an issue where a hotspot instance appeared to be assigned to the wrong theme
- I/O Status: fixed mismatched I/O pin names in the table and legend
- I/O Status: fixed digital input/output pin re-initialization bug after using pulse counter
- IEC 60870-5 Client: fixed common address validation on the client side
- IEC 60870-5 Client: fixed database error in the API endpoint for database entries
- IEC 60870-5 Server: fixed IEC60870-5 Server should not restart after disabling WAN access
- Impulse Counter: fixed Impulse Counter add button tooltip to show a hint when all available options have been selected
- IPsec: fixed hint overlap
- L2TP: fixed validation requirements for client and server configurations
- Mobile Utilities: fixed OpenVPN status SMS message
- Modbus Client: fixed Modbus test button tooltips to display hints when testing
- Modbus Client: fixed database error in the API endpoint for database entries
- Modbus Client: fixed modbus client request configuration actions overflowing
- OPC UA Client: fixed database error in the API endpoint for database entries
- OPC UA Server: fixed error status not displaying messages
- OpenConnect: fixed hint overlap
- OpenVPN: fixed hint overlap
- SNMP: fixed minor webui validation bug
- TR-069: fixed OUI setting now it's dynamically set
- System
- NTP Client: fixed unnecessary service restart when network interface changes state
- Package Manager: fixed the installation of backup archive packages in cases of low free flash space
- Network
- CVE Patches
- CVE-2025-13837 - 2.1 (LOW)
- CVE-2025-61099 - 7.5 (HIGH)
- CVE-2025-61100 - 7.5 (HIGH)
- CVE-2025-61101 - 7.5 (HIGH)
- CVE-2025-61102 - 7.5 (HIGH)
- CVE-2025-61103 - 7.5 (HIGH)
- CVE-2025-61104 - 7.5 (HIGH)
- CVE-2025-61105 - 7.5 (HIGH)
- CVE-2025-61106 - 7.5 (HIGH)
- CVE-2025-61107 - 7.5 (HIGH)
- CVE-2026-30874 - 1.8 (LOW)
RUTC_R_00.07.22.4 | 2026.06.12
- Improvements
- System
- Backup: restored backup generation to backup without API
- System
RUTC_R_00.07.22.3 | 2026.05.19
- Fix
- System
- Backup: fixed saving of crontabs
- System
- CVE Patches
- CVE-2026-31431 - 7.8 (HIGH)
- CVE-2026-43284 - 7.8 (HIGH)
RUTC_R_00.07.22.1 | 2026.04.13
- Improvements
- System
- ustream-ssl: updated version to 2026-03-01
- System
- Fix
- Services
- IEC 60870-5 Client: fixed missing serial support validation checks
- IEC 60870-5 Server: fixed package dependency issues and missing serial support validation checks
- Modbus Client: fixed test requests due to missing broadcast option
- RMS: fixed configuration permission issues that caused connection problems
- System
- Backup: fixed custom uci-default script execution
- Backup: fixed ability to reset user password to device default password
- Services
RUTC_R_00.07.22 | 2026.03.25
- Initial firmware release