RutOS 7.24 and OT Networks: What Changes for Teltonika Industrial Routers

Teltonika released RutOS 7.24 on 26 June 2026. Read the headline and it looks like an Altos release. VXLAN, Docker and NetBird took the announcement, and all three are exclusive to the Altos CAP700.

Look at the rest of the changelog and a different picture appears. For the industrial range, RutOS 7.24 is an operational technology release. CANopen Client, MQTT topic variables, SSO, encrypted file transfer and a faster TR-069 stack all point the same way. Teltonika is closing the gap between how OT engineers run a router estate and how IT security expects any managed device to behave.

This guide covers what changes for the RUT, RUTX, RUTM and OTD ranges. It also identifies which features apply to which hardware, because several do not apply everywhere.


What lands where

Firmware releases are announced platform-wide. Features are not always platform-wide. The table below separates them.

FeatureWhat it doesApplies to
CANopen ClientPolls CANopen nodes directly from the routerRUT204 only. Requires a native CAN interface.
MQTT topic variablesEmbeds router name, serial and LAN MAC into MQTT topicsAll RutOS devices with Data Sender and Event Juggler
SSO loginDevice login through a corporate identity providerPlatform-wide [SPEC TO VERIFY: supported identity providers]
SFTP and FTPS in Data SenderEncrypted file export with certificate or SSH key authPlatform-wide
TR-069 expansionTR-181 Amendment 20 parameters, faster session setupPlatform-wide
Operator priority listRanked operator preference inside the allowlistAll cellular RutOS devices
Third Party Packages tabCurated partner packages in Package ManagerPlatform-wide [SPEC TO VERIFY per model]
PPSK import, export and generationBulk per-user Wi-Fi key managementWi-Fi models [SPEC TO VERIFY per model]
VXLANLayer 2 overlay across a routed WANAltos CAP700 only
DockerContainer hosting on the routerRUTC series and Altos CAP700 only
NetBirdWireGuard mesh VPNAltos CAP700 only

The most common misreading of this release: CANopen Client does not arrive on the RUT200, RUT901, RUTX50 or OTD500. None of those routers has a CAN interface. Firmware cannot add a physical bus. The feature applies to the RUT204, which is the only Teltonika router with native CAN FD hardware.


CANopen Client: the router becomes an OT data collector

The RUT204 already read raw CAN frames and forwarded them over cellular. That is useful for telematics, where a fleet platform decodes the frames at the far end. It is less useful in a fixed OT installation, because raw CAN is not self-describing.

CANopen adds an object dictionary on top of CAN. Each node exposes indexed objects with defined data types. A CANopen client can therefore request a specific object by index and sub-index, and receive a value it understands.

With CANopen Client in RutOS 7.24, the RUT204 polls those objects itself. It then republishes them over MQTT, HTTPS or Modbus TCP. No PLC and no industrial PC sit in between.

Where this changes the bill of materials

  • Standby generators. Engine controllers on CANopen expose RPM, coolant temperature, fuel level, run hours and fault codes. The RUT204 polls them and publishes to SCADA over MQTT.
  • Variable speed drives. CiA 402 profile objects such as status word, actual velocity and error register become readable directly.
  • Water and wastewater. Pump station telemetry from CANopen instrumentation, alongside Modbus TCP from the PLC, on one device.
  • BESS and renewables. Battery management systems frequently expose CANopen. Cell voltages and state of charge move straight into the monitoring platform.

The saving is real. A CAN gateway, a cellular router and a separate remote-access arrangement collapse into one managed device.

Before you specify it: confirm your node’s CANopen profile and object dictionary. CANopen Client reads defined objects. It is not a decoder for proprietary J1939 PGNs, which the RUT204 handles through a separate mechanism. Ask the equipment vendor for the EDS file before commissioning.


MQTT topic variables: identity without a mapping table

Every RutOS router with Data Sender can publish telemetry to an MQTT broker. Until now, the topic string was static per device. Two hundred routers meant two hundred configurations, or a payload field carrying the device identity and a mapping table in the backend.

RutOS 7.24 allows the topic to contain variables. Router name, serial number and LAN MAC address are substituted at publish time.

The practical effect is that one configuration template works across the fleet. A topic such as site/telemetry/[serial]/modbus resolves differently on every device. As a result, brokers, time-series databases and historians route by topic alone. Commissioning gets shorter, and a replaced router publishes correctly the moment its serial appears.

This matters most where an OT data platform enforces a topic hierarchy. Sparkplug B deployments and ISA-95 asset trees both depend on structured topics rather than payload inspection.


SSO: closing the local-account problem

Field routers accumulate local admin accounts. An engineer leaves, and their credentials remain on 300 devices in cabinets across the country. Nobody removes them, because removing them means touching every device.

RutOS 7.24 adds SSO, so device login authenticates against a corporate identity provider. Deprovisioning a user centrally removes their access to the fleet. Audit trails point back to a real identity rather than a shared root password.

This is the change in this release most likely to matter to an IT security review. OT device access has been a standing audit finding for years. Because RutOS now supports federated login, industrial routers stop being the exception on the asset register.

Keep a break-glass local account. If the identity provider is unreachable and the router’s WAN is down, federated login cannot complete. [SPEC TO VERIFY: confirm which identity providers are supported before writing SSO into a design.]


SFTP and FTPS: encrypted export for OT logging

Data Sender pushes files as well as messages. Log bundles, CSV exports and event snapshots move from a router to a central server on a schedule. Until this release, plain FTP was the mechanism.

Most IT security policies now block plain FTP outright. RutOS 7.24 adds SFTP and FTPS, with certificate or SSH key authentication. Unattended transfers therefore work without an embedded password and without an exception in the firewall policy.

For regulated environments, this closes a compliance gap that previously forced an intermediate jump host between the OT network and the data centre.


TR-069: faster provisioning at fleet scale

TR-069, also called CWMP, is how ISPs and managed service providers provision customer premises equipment. RutOS 7.24 improves it in two ways.

First, session establishment is much faster. Teltonika reports a reduction from roughly two minutes to around fifteen seconds. On a fleet of 500 devices, that is the difference between a rollout window and an overnight job.

Second, the data model expands with parameters from TR-181 Issue 2 Amendment 20. TraceRoute diagnostics, Wi-Fi SSID details and radio information are exposed to the ACS. Engineers can therefore diagnose a link from the management platform rather than dialling into the device.

If you already run GenieACS, FreeACS or a commercial ACS, this is a straightforward upgrade. If you use Teltonika RMS instead, TR-069 is not required, and RMS remains the simpler path for most UK deployments.


Operator priority: predictable network selection

Multi-IMSI and roaming SIMs give a router several usable networks. Left alone, the modem attaches to whichever it finds first. That is rarely the network you want.

RutOS 7.24 adds a priority order inside the operator allowlist, and improves home-operator selection logic. You can therefore state a preference: attach to the primary network first, a named second choice next, and anything else only as a last resort.

For remote pumping stations, trackside cabinets and border-crossing vehicles, this removes a persistent support burden. Devices stop latching onto a weak roaming partner when a strong home network is available.

This is configured in RutOS. It is not automatic. Set the priority list before you ship the router, because reaching a device on a bad network to fix its network preference is exactly the problem you are trying to avoid.


Third-party packages and PPSK

The Package Manager gains a Third Party Packages tab. Packages from cooperating maintainers appear separately from Teltonika’s own components. The separation matters for supportability, because an auditor can see at a glance what is vendor-supplied and what is not. Our Package Manager explainer covers installation and rollback.

PPSK management also improves, with bulk import, export and automatic key generation. Where a Teltonika router serves Wi-Fi in a depot, workshop or contractor area, each user or device can hold a unique key without a spreadsheet behind it. Revoking one key does not force a rekey of the whole site.


What did not come to the industrial range

VXLAN, Docker and NetBird are Altos CAP700 features in this release. Docker also remains available on the RUTC series. It did not arrive on the RUT, RUTX, RUTM or OTD ranges, and it will not, because those devices carry megabytes of flash rather than gigabytes.

If container hosting or layer 2 overlay networking is a requirement, that decision drives the hardware choice rather than the firmware version. Our Altos CAP700 and RutOS 7.24 guide covers those three features in detail.


Rolling 7.24 across an existing estate

Do not update 300 devices on a Friday afternoon. A staged approach costs an afternoon and prevents a fleet-wide outage.

  • Take a configuration backup first. Export from the WebUI, or pull backups through RMS, before any device is touched.
  • Pilot on two devices. Pick one on a good signal and one on a marginal one. Marginal sites surface modem firmware interactions that good sites hide.
  • Check custom packages. Anything installed through Package Manager may need reinstalling after a major firmware step.
  • Roll out in waves through RMS. RMS handles staged firmware rollout and reports failures per device. Credits are consumed per managed device per month, and are available through our RMS credits page.
  • Keep settings enabled. FOTA preserves configuration by default, but verify this on the pilot devices rather than assuming it.

Sites reachable only over a dynamic-IP SIM behind carrier-grade NAT are the ones that hurt when an update goes wrong. A fixed IP SIM and a VPN give you a route back in that does not depend on the router calling home.


Frequently asked questions

Does RutOS 7.24 add CANopen to the RUT200 or RUTX50?

No. CANopen Client requires a physical CAN interface, and neither router has one. Firmware cannot add a hardware bus. The RUT204 is the only Teltonika router with native CAN FD hardware, so it is the only model where CANopen Client applies.

Is RutOS 7.24 an OT-focused release?

For the industrial range, yes. CANopen Client, structured MQTT topics, SSO, encrypted file export and improved operator selection all address problems specific to operational technology estates. The headline features, VXLAN, Docker and NetBird, are Altos-only and address enterprise edge networking instead.

Can I run Docker on a RUT200 or RUTX50 after updating?

No. Docker on Teltonika hardware is limited to the RUTC series and, from this release, the Altos CAP700. It is a hardware constraint. The RUT and RUTX ranges do not carry the flash storage or RAM to host containers.

Does SSO replace local admin accounts on Teltonika routers?

It supplements them. SSO authenticates administrators against a corporate identity provider, which solves the deprovisioning problem across a fleet. However, you should retain a break-glass local account. If the WAN is down, the router cannot reach the identity provider and federated login will not complete.

How do MQTT topic variables help a large deployment?

One configuration template works across every device. The topic string contains placeholders for router name, serial number or LAN MAC, which RutOS substitutes at publish time. Brokers and historians then route messages by topic structure alone, with no per-device mapping table in the backend.

Which Teltonika routers get the RutOS 7.24 update?

RutOS 7.24 is released across supported RUT, RUTX, RUTM, RUTC, TRB, OTD and Altos devices, though individual features depend on hardware. Check the firmware page for your specific model in RMS or on the Teltonika wiki. End-of-life models may not receive it.


Related products and further reading

The Teltonika RUT204 is the model most affected by this release, and is held in UK stock. For the Altos-specific features, read our Altos CAP700 and RutOS 7.24 guide. Fleet management is covered in our Teltonika RMS explainer, and remote access options in our VPN on cellular routers explainer. Browse the full Teltonika 4G router range and Teltonika 5G router range. If you are specifying hardware against a firmware feature, call our UK-based technical support team on 0300 124 6181 before you order.