Doc No. Robustel_SA_20260610
Updated June 10th, 2026
Robustel has released a firmware security update for all RobustOS devices. This update addresses security vulnerabilities related to OpenSSH and Nginx in the RobustOS firmware.
If you are utilizing Public IP SIMs or believe that your network requires enhanced protection, we recommend downloading and installing the latest firmware update through the RCMS. Should you have any questions or need assistance, please do not hesitate to contact the Robustel Support Team.
DETAILS
This section summarizes the potential impact that this security update addresses. Descriptions use CWE™, and base scores and vectors use CVSS3.0 standards.
CVE IDs | Summary | Base Score | Vector
|
CVE-2025-21920
| In the Linux kernel, improper validation of underlying device types during VLAN initialization can trigger an out-of-bounds read, enabling local users to expose sensitive kernel function addresses. | 7.1
| CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L |
| CVE-2025-39864 | In the Linux kernel, premature freeing of shared beacon elements during network updates can trigger a use-after-free vulnerability, enabling attackers to cause kernel memory corruption or a system crash when cmp_bss() attempts to access the deallocated memory.
| 7.8 | CVSS:3.1/AV:L/AC:L/PR:
L/UI:N/S:U/C:H/I:H/A:H
|
SECURITY UPDATES
The following table lists the products affected, versions affected, and the updated version that includes this security update.
To upgrade the device firmware,
- you can either remotely deploy the corresponding firmware version to the device directly through RCMS.
- or download the firmware from the Robustel knowledge base to perform a local upgrade.
CVE IDs Addressed | Product Name | Affected Versions | Updated Version |
| R3000 Series/R3000LG/
R5020 Series/R2110
R2111/R2120 | V5.x | V5.6.0 |
| R5020 Series/
R2110/R2111/R2120
| V5.x | V5.6.0 |
Mitigation
Upgrade to version V5.6.0
Remark:
- For R2110 / R5020 / R5020Lite with v5.x: Upgrade to V5.2.2 or higher before upgrading to V5.6.0.
- For other models with v5.x: Upgrade to V5.6.0 directly.
- For all model with legacy v3.x: Please contect Technical Support for assistance.
Initial Publication Date
June 10th, 2026
REVISION HISTORY
Revision | Date | Description |
1.0 | June 10th, 2026 | Initial release
|
SUPPORT
For any inquiries regarding this security bulletin, please reach out to the Robustel Support Team.