Industrial Router Provenance: Who Really Makes Yours?

who makes your industrial iot router - we discuss industrial router provenance
Hardware / Supply Chain Security

Who Really Makes Your Industrial Router? Provenance, China and the UK Buyer

Almost every industrial router sold in Britain has Chinese silicon inside it, and several of the best known brands are Chinese companies outright. So is provenance a real risk, or just a talking point? We look at Teltonika, Robustel, InHand and Milesight, test a newcomer called DONYX, and give you a price versus provenance scale and the quick checks that keep you out of trouble.

IoTPortal.co.uk  |  October 2026  |  22 min read
In short

Industrial router provenance is not a simple question of "Chinese or European". Teltonika builds in Lithuania but uses Chinese cellular modules; Robustel, InHand and Milesight are Chinese companies with European offices; a few German makers still build at home. The real risks are a supplier that cannot be identified, a support chain that can vanish, a firmware owner nobody can name, and a sanctions link you did not check. Match the scrutiny to the lifetime and criticality of the job.

Why industrial router provenance matters now

For most of the last decade, choosing an industrial cellular router was a features and price exercise. Does it have the bands, the serial port, the VPN, the cloud management? What does it cost at 50 units? Where it was designed, who assembled it and who owns the firmware rarely came up outside defence and a handful of critical infrastructure buyers.

That has changed, for four reasons that have nothing to do with fashion.

First, regulation now follows the device. Since 1 August 2025 the EU Radio Equipment Directive cybersecurity delegated act (Regulation 2022/30) has applied to internet connected radio equipment, which includes every cellular router placed on the EU market, with the EN 18031 standards as the route to compliance. The EU Cyber Resilience Act went further: from 11 September 2026 manufacturers must report actively exploited vulnerabilities and serious incidents, including on products already in the field, with full obligations from 11 December 2027. Both rules need an identifiable manufacturer who is still around to meet them.

Second, sanctions have reached the component trade. Western enforcement against Russian procurement networks has named Hong Kong trading shells and Russian industrial electronics makers, including at least one industrial router manufacturer. A UK buyer now has to think about where the money goes, not just where the box comes from.

Third, cellular modules became a political subject. In 2023 the US House Select Committee on the CCP asked the FCC to look at Quectel and Fibocom modules, which sit inside a very large share of the world's IoT routers.

Fourth, and most practically for anyone who has to support a fleet for eight years, brands disappear. The UK car market has just shown how quickly that can happen.

The uncomfortable truth: nearly everything is part Chinese

Before naming brands it is worth separating the layers, because "who makes it" has at least five answers for any router.

LayerWhat it meansWhy a buyer should care
Brand ownerThe company whose name is on the box and who sells itWarranty, support and legal responsibility for the product
Legal manufacturerThe party named on the Declaration of ConformityThe one accountable under RED, UKCA and the CRA
Hardware designerWho designed the board, sometimes an ODMWho can fix a hardware fault or revise a design
AssemblerThe factory that builds the PCB and final unitQuality, lead times and exposure to trade disruption
Cellular moduleQuectel, Fibocom, Telit, Sierra, u-blox and othersRadio firmware, certification and module end of life
Firmware and cloudWho writes the OS, signs updates and runs the management platformPatch speed, remote access and where your data goes

On the module layer alone, a large part of the market runs on Chinese silicon. Quectel modules are fitted inside routers from European, American and Asian brands alike. When engineers on Quectel's own forum ask for firmware for the EC25 module inside a Teltonika RUT240, they are describing something completely normal. "European" in this market almost always means European design, assembly and accountability around a partly Asian bill of materials.

Under the hood: Linux, OpenWrt and the GPL

The same layering applies to software. Most industrial router operating systems, whatever the brand calls them, are Linux distributions, and many are built on OpenWrt, the open source router platform. Teltonika's RutOS is one; it is normal and, done well, a strength, because OpenWrt is mature, widely reviewed and patched by a large community. Our list of OpenWrt in industrial routers shows which of 35 manufacturers build on it, and what runs under the rest.

It also gives buyers a lawful provenance check that few use. The Linux kernel is licensed under the GNU General Public License, and much of an OpenWrt system is GPL or LGPL code. Anyone who ships those binaries in a product has to make the corresponding source code available. Teltonika, for example, publishes SDK source packages for its router families on an open source page that cites the GPL, LGPL, Apache and MIT licences it ships under.

Ask any supplier for the GPL source of the exact firmware you are buying. A vendor that controls its own firmware can supply it quickly. One that cannot either does not really own its software stack or is not meeting its licence obligations, and both are worth knowing. The source also tells you what the firmware is built on, which matters more than the brand name on the web interface. OpenWrt 19.07, for instance, reached end of life on 4 March 2022, after which the project stopped fixing even severe security problems. A router still shipping on a base that old is entirely dependent on its vendor backporting fixes, and you should ask how they do it.

That is not a scandal. It is how the electronics industry works. It does mean the useful question is not "is there anything Chinese in it?" but "which layers do I need to trust, and can I see who controls each one?"

The established brands, layer by layer

Teltonika: Lithuanian design and assembly, global components

Teltonika is the clearest European example. The group was founded in Kaunas in 1998 and is headquartered in Vilnius. Its networking products are designed in Lithuania and built by Teltonika EMS at plants in Vilnius and Moletai; the company says idea generation, design, manufacturing, assembly and quality control all sit inside the group, and the Moletai technology centre opened in 2022 on a reported 34 million euro investment. Lithuania's official promotion site credits the group with more than 25 million IoT devices built in those two facilities, and a new printed circuit board factory has been under construction.

The cellular radio inside is a different story. Distributors openly list the RUT241 as the Quectel variant, and the RUT240 family has shipped with Quectel EC25 modules. RutOS is built on OpenWrt, like most industrial router operating systems. Teltonika also has an unusually visible bet on supply-chain independence beyond the router: it has a technology agreement with Taiwan's ITRI aimed at semiconductor design and fabrication capability in Lithuania.

So the honest description is a European manufacturer with full control of design, assembly, firmware and cloud, using Chinese and other Asian modules and chips. For most UK buyers that is about as good as provenance gets at volume pricing.

Robustel: a Guangzhou manufacturer with a European footprint

Robustel's name gives nothing away, and plenty of installers would struggle to say where it is from. It is a Chinese company, Guangzhou Robustel, founded in Guangzhou in 2010, with its own production facility there. It opened branches in Germany, Australia and Japan in 2014, the Netherlands in 2015, and the UK and US in 2017, and it publishes both EU and UK Declarations of Conformity alongside a security centre with CVE-tagged advisories.

That is a perfectly reasonable profile for a serious vendor. Robustel designs its own hardware, writes RobustOS, runs RCMS and has been through public vulnerability disclosure, including a Cisco Talos report on the R1510, and it now publishes CVE-tagged advisories. The point is simply that Robustel is a Chinese manufacturer with European offices, not a European manufacturer, and a buyer with a policy on Chinese equipment should know which they are buying.

InHand Networks: a listed Beijing company

InHand Networks is Beijing InHand Networks Technology Co., founded in 2001 and listed on the Shanghai STAR Market since February 2020 under code 688080. At IPO, the State Grid Corporation of China was reported as its second largest customer. It sells industrial routers, edge gateways and cloud management across Europe and the UK.

From a provenance point of view, a stock exchange listing is actually helpful. Listed companies publish accounts, shareholders and risk disclosures, which makes InHand more transparent than many private firms of any nationality. Its Chinese domicile and state utility customer base are facts buyers in sensitive sectors will want on the file.

Milesight: Xiamen, from cameras to IoT

Milesight is Xiamen Milesight IoT Co., based in Xiamen, Fujian, and describes itself as delivering IoT and video surveillance products since 2011. Its LoRaWAN sensors, gateways and cellular routers are widely used in UK smart building and agriculture projects, and its industrial routers have had their own disclosed vulnerabilities, including CVE-2023-43261.

Milesight shows how much of the UK IoT stack now comes from Chinese firms by default. If your buildings estate runs Milesight sensors into a Milesight gateway, the provenance question applies to the whole chain, not just the router.

The genuinely "made in Germany" option

It does exist. INSYS icom in Regensburg says its software and hardware development takes place there and its routers are manufactured almost exclusively in Germany, and it has a BSI IT security certificate for the MRX3 LTE router. Expect to pay noticeably more, and expect that the cellular module inside may still come from Asia. "Made in" claims nearly always describe assembly and design, not every chip.

Where that leaves the big names

Teltonika is European with Chinese modules. Robustel, InHand and Milesight are Chinese companies with European offices, local stock, UK paperwork and public security processes. INSYS icom is German made at a German price. None of these is hidden, and all of them can be identified, contacted and held to account. That is the baseline a new brand has to meet.

Is EU or UK manufacture a pipe dream?

For the whole bill of materials, yes, at least for now. Cellular baseband chips come from a handful of vendors, modules are dominated by Quectel and Fibocom at the volume end, and passive components, enclosures and power supplies come overwhelmingly from Asia. There is no realistic all-European cellular router at mainstream prices, and the UK has no volume industrial router maker of its own.

For the layers that matter most to a buyer, no. European design, European final assembly, European firmware and a European legal manufacturer are all available today, from Teltonika at volume and from smaller German specialists at a premium. Teltonika's investment in its own PCB plant and its Taiwanese semiconductor partnership show the direction of travel: pull more layers home, one at a time.

The sensible target for most UK projects is therefore not "no Chinese parts". It is "an accountable manufacturer I can identify, a support chain that will outlast the deployment, firmware I can patch, and a supply chain with no sanctioned parties in it".

The long-term viability lesson from Chinese car brands

Industrial buyers can learn a lot from what has just happened on UK forecourts. Chinese brands took almost 10% of UK new car sales in 2025 and kept growing in 2026. Most of them are well funded and here to stay.

Skywell was not. Its UK importer, Innovation Automotive, ceased trading with immediate effect in June 2026, leaving Skywell and DFSK without an official UK distributor. Fewer than 150 Skywell BE11s had been registered in two years. Owners were left uncertain about warranty and parts; DFSK van owners were told warranties would no longer be available. The importer blamed the investment needed to compete in a market flooded with new Chinese entrants.

The manufacturer did not fail. The local partner did, and for UK customers the result was the same. Industrial routers work exactly like this. Your warranty, RMA process, firmware support and often your cloud contract run through a UK or European distributor. If that company is new, thinly capitalised and the only route to the brand, it is a single point of failure for every device you deploy, however good the hardware is.

The question to ask

If this distributor stopped trading tomorrow, who would honour my warranty, ship replacement units and publish firmware fixes for the next seven years? If nobody can answer that in writing, price the risk in.

Security and geopolitics: what is real and what is noise

Modules and remote control

The US House Select Committee's 2023 letter argued that Chinese cellular modules could in principle be used to exfiltrate data or disable devices, and asked whether the FCC could add Quectel and Fibocom to its Covered List. Quectel disputed the letter's understanding of how its modules work. As of this writing the UK has taken no equivalent step on IoT modules. For most UK industrial users this is a watch item, not a reason to rip out working kit, but it is a reason to know which module is in your fleet so you can respond if policy changes.

Firmware is the bigger practical risk

Whoever signs firmware updates and runs the cloud management platform can change what the router does. In practice, the much more common failures are unpatched firmware, exposed management interfaces and default credentials, and they affect every brand, as our cellular router security hardening guide sets out. Provenance and hygiene are the same discipline: you cannot patch quickly if you cannot identify who publishes the patch.

Sanctions are where buyers actually get caught

Sanctions are strict and do not care how cheap the router was. The US designated Radiofid Systems, the St Petersburg company behind the iRZ industrial router brand, in August 2024, and the US Justice Department has prosecuted a Hong Kong based network that used trading shells, including one called Alice Components, to route US microelectronics to Russia. The lesson is not about any one brand. It is that industrial router makers and component traders do end up on lists, and anyone in the payment chain needs to have checked.

In the UK, the single authoritative source is now the UK Sanctions List published by the FCDO; OFSI's separate consolidated list closed on 28 January 2026. Check the brand owner, the legal manufacturer on the Declaration of Conformity, the distributor and anyone you pay.

Case study: DONYX, the new name on the shortlist

DONYX is a useful test because it has started appearing in European conversations with an interesting range and very little public history. Here is what can be verified from public records and DONYX's own site, and what a buyer would still need to ask.

The products

The range is genuinely unusual. The S series is a compact single-module router with LTE Cat 4, Cat 6 or 5G RedCap, two 10/100 Ethernet ports with PoE in and out, Wi-Fi and GNSS. The X series adds RS-232, RS-485, seven GPIO and four 10/100 Ethernet ports, in single or dual cellular module versions, such as the RX44x2 and RX54x2. The M series is where it stands out: the RM45x2 and RM45x4 carry two or four LTE modules, and the RM55x2 and RM55x4 two or four 5G RedCap modules, with five Gigabit Ethernet ports, RS-485 and dual-band Wi-Fi.

Four independent cellular modules in one industrial box is not something the mainstream brands sell as standard, and a dual modem router is a different thing from a dual SIM router: two radios can hold two live connections at once instead of switching. For resilient remote sites, that is a real engineering argument. It sits well alongside a multi-network SIM strategy, and DONYX's early 5G RedCap range puts it in the same race as Teltonika, Robustel and others.

The company claims

DONYX's About page says the company was founded in 2005, delivered its first equipment in 2006, moved into audio and tour guide equipment from 2013 and added antenna production in 2024. Its router pages say it has supported 800 companies. The About page itself was first published in August 2025, according to its page metadata.

The distributor page says DONYX has distributors in 140 countries. The listing beneath it shows DONYX itself as the global contact, with a +86 769 telephone number (the Dongguan code in Guangdong), plus two named partners: EasyNet Technologies UAB in Vilnius, Lithuania, and Central Asia IoT in Almaty, Kazakhstan. Every other region points back to DONYX.

The UK route

Companies House shows EasyNet Technologies Ltd, incorporated on 18 March 2026 as EasyNet Solutions Ltd and renamed on 30 April 2026, registered in Suffolk with wholesale telecoms equipment as its business. In other words the UK supply route is a few months old. Its first accounts are not due until December 2027.

What we would ask before buying

None of this says anything bad about the hardware or the people. It does put DONYX at a different point on the provenance scale from the established brands, simply because so much is unknown. Before deploying it anywhere that matters, we would want written answers to these:

  • What is the legal name and country of the manufacturer named on the EU and UK Declarations of Conformity for each model?
  • Which factory builds the units sold in the UK, and which cellular modules are fitted?
  • Who owns and develops the router operating system, and how are updates signed?
  • Will you supply the GPL source for the firmware, and which OpenWrt and Linux kernel versions is it built on?
  • Where is the remote management platform hosted, and by which legal entity?
  • What is the published security update commitment, and is there a vulnerability disclosure process ready for CRA reporting?
  • What did the company founded in 2005 trade as, and when was the DONYX brand first used on routers?
  • Who honours warranty and RMA if the UK distributor stops trading?
  • Can you name three reference customers in the UK or EU, with quantities and deployment dates?

If DONYX or its European distributor answers them, we will update this article with the response.

The price versus provenance scale

There is no single right answer, because a twelve-month construction site camera and a fifteen-year water telemetry outstation are different risks. The scale below grades suppliers into four provenance tiers and then asks how much provenance your project actually needs.

TierWhat it looks likeExamplesTypical price position
A: SovereignEU or UK design, assembly, firmware and legal manufacturer; long published support; formal security certificationGerman specialist makers such as INSYS icom; Teltonika for most purposesHighest to mid
B: AccountableEstablished vendor of any nationality with years of public history, own firmware, published DoCs, security centre, local entity and stockRobustel, InHand, MilesightMid to low
C: EmergingCapable product, short or unclear public history, new local distributor, limited referencesNew entrants such as DONYX todayOften competitive; unusual features
D: AnonymousWhite label or marketplace units, no identifiable manufacturer, no update policyGeneric marketplace routersLowest

Where should your project sit?

Move the sliders to describe the deployment. The marker shows the minimum provenance tier we would accept.

How long the router will stay installed before planned replacement.
From a temporary convenience link to safety or essential service infrastructure.
Customer approved vendor lists, NIS2 or UK CNI duties, public sector security clauses, selling into the EU.
The more units, the more a support failure or recall costs.
The price difference a cheaper or newer supplier is offering.
Tier DTier CTier BTier A
Minimum: Tier B, Accountable

Adjust the sliders to see a recommendation.

The logic is deliberately simple. Service life, impact, regulation and fleet size push the requirement up. A large saving can justify accepting an emerging supplier on lower-stakes jobs, but it never moves a critical or regulated deployment below Tier B, because no discount covers a fleet you cannot patch or a payment you should not have made. Treat the result as a starting point for your own policy, not a compliance ruling.

Quick checks that keep you out of trouble

None of these needs a lawyer or a lab. Together they take less than an hour for a new supplier, and they would have flagged every risk discussed above.

  • Screen every party on the UK Sanctions List. Brand owner, legal manufacturer, distributor and anyone you pay. Use the UK Sanctions List; if you sell into the EU or US, add the EU sanctions map and the OFAC search.
  • Read the Declaration of Conformity. It must name the manufacturer and its address. Check the UK version exists if you are deploying in Great Britain, and that RED cybersecurity (EN 18031) is listed for EU supply.
  • Look up the distributor on Companies House. Companies House shows incorporation date, previous names, officers, persons with significant control and whether accounts are filed. A company months old is not a problem in itself, but it is a fact to weigh.
  • Find out which cellular module is fitted. Ask, or read it from the router's status page. It tells you whose radio firmware you depend on and lets you respond if module policy changes.
  • Check the FCC ID if there is one. The FCC ID database names the grantee and often publishes internal photographs showing the module and board.
  • Ask for the GPL source. Linux based router firmware must come with its source on request. Getting it shows the vendor controls its software and reveals the OpenWrt and kernel versions underneath; an end of life base means you depend on the vendor for every security fix.
  • Ask who signs the firmware and runs the cloud. Get the legal entity and hosting location in writing, plus the support period for security updates.
  • Look for a security track record. A vendor with published advisories, CVEs and a disclosure contact is easier to trust than one with none. Search the NIST NVD for the brand.
  • Test the history. Does the claimed founding date match the trademark, the domain age and the company records? Mismatches are not proof of anything, but they are worth a question.
  • Get the exit plan in writing. Who honours warranty and firmware if the local partner fails? Is there a second distributor, or a direct route to the manufacturer?
  • Ask for references you can call. Named customers, quantities and how long the units have been in the field.
Keep a file

Write down what you checked, when and what the supplier told you. If a sanctions designation, a vulnerability or a distributor failure turns up later, a dated record that you did reasonable due diligence is worth far more than the time it took.

So, is there really a problem?

Not in the way the headlines suggest. Chinese manufacturers make good industrial routers, Chinese modules sit inside European ones, and pretending otherwise helps nobody. Teltonika, Robustel, InHand and Milesight can all be identified, contacted and held to account, and each sits comfortably in the accountable tier or above.

The problem is opacity. A supplier whose manufacturer you cannot name, whose firmware owner is unclear, whose local support is one new company deep, or whose supply chain you have not screened, is a risk whatever flag it flies. New entrants like DONYX may bring genuinely useful engineering, and four-modem RedCap is exactly the kind of thing the market needs. They earn a place on critical sites the same way everyone else did: by answering the questions in writing.

Frequently asked questions

Are Teltonika routers made in China?

No. Teltonika designs its routers in Lithuania and builds them at its own plants in Vilnius and Moletai. Like almost every cellular router maker, it uses cellular modules and chips from Asian suppliers, including Quectel modules in some models.

Is Robustel a Chinese company?

Yes. Robustel was founded in Guangzhou, China, in 2010 and manufactures there. It has offices in Germany, the Netherlands, the UK and elsewhere, and publishes EU and UK Declarations of Conformity.

Can I buy an industrial router with no Chinese components?

Not realistically at mainstream prices. Even routers designed and assembled in Germany or Lithuania usually rely on Asian cellular modules, chips and passive components. A better target is an accountable European or UK legal manufacturer with clear firmware ownership.

Who makes DONYX routers?

DONYX says it is an electronics and software manufacturer founded in 2005, and lists a Dongguan, China, telephone number as its global contact. European distribution runs through EasyNet Technologies in Lithuania, with a UK company formed in 2026. Ask for the manufacturer named on each model's Declaration of Conformity.

What operating system do industrial routers run?

Most run Linux, and many are built on OpenWrt, including Teltonika's RutOS. Because the Linux kernel and much of OpenWrt are GPL licensed, vendors must provide the source code, which also shows which OpenWrt and kernel versions the firmware is based on.

How do I check whether a router supplier is sanctioned?

Search the brand owner, legal manufacturer, distributor and payee on the UK Sanctions List, which became the single UK source in January 2026. Add the EU and US lists if you sell into those markets, and keep a dated record of the check.

Does the Cyber Resilience Act apply to industrial routers?

Yes, for products on the EU market. Vulnerability and incident reporting applies from 11 September 2026, including to products already sold, and full requirements apply from 11 December 2027. The RED cybersecurity delegated act has applied since 1 August 2025.

Related reading

Sources: Teltonika IoT Group FAQ and Teltonika EMS (manufacturing in Vilnius and Moletai); Lithuania.lt (25 million devices, PCB factory); LRT (Moletai technology centre); Sectron and Quectel forums (Quectel modules in RUT240 and RUT241); Robustel company profile and documentation (founding, Guangzhou production, branches, EU and UK DoCs); Shanghai Stock Exchange and DealStreetAsia (InHand Networks listing and customers); Milesight company releases (Xiamen, since 2011); INSYS icom (Regensburg manufacture, BSI certificate); Teltonika open source software page (GPL source packages); IoTPortal, OpenWrt in industrial routers (manufacturer list); OpenWrt developers list (19.07 end of life, 4 March 2022); US House Select Committee on the CCP letter to the FCC, August 2023; US Department of Justice (Marchenko case, Alice Components); OFAC SDN list, 23 August 2024 (Radiofid Systems); FCDO and OFSI (UK Sanctions List as single source from 28 January 2026); EU Regulation 2022/30 and EN 18031 (from 1 August 2025); EU Cyber Resilience Act timeline; Which?, Fleet News and Autocar (Skywell UK importer closure, June 2026); SMMT figures via Electrifying (Chinese brand UK share 2025); DONYX website (catalogue, About, Distributors and Contact pages, accessed October 2026); Companies House (EasyNet Technologies Ltd, 17101955). As of October 2026.