You do not need to frequently upgrade TLS versions to be secure. TLSv1.2 will likely be fine for many years and TLSv1.1 has been fine for 11 years. If you do need to upgrade, it won't be often, but the QA is the only hard part.
> trust anchors always change
Indeed an issue, especially with the public PKI, but you can roll your own root certificate with a lifespan of 50 years or something. This is somewhat dangerous as there's now a non-expiring trust anchor instead of the usual 1-3 year key rotation, but it's still practical, especially if HTTPS is only a layer of protection around your already signed firmware.
> there's no guarantee that today's state of the art won't be completely incompatible with TLS implementations in 5 years
Well, TLS is designed to negotiate the version to avoid this exact issue, but even if TLSv1.x is not backwards compatible there is nothing blocking the update server from supporting the older version?
> Many older routers simply cannot use HTTPS for updates because newer versions of OpenSSL simply won't fit on the flash.
OpenSSL is far from the only implementation here. BearSSL is only 25KB and there are even microcontrollers with their own TLS stack built into hardware, like the CC3220 from TI, which I've been using at my job. There are concerns there too with updating TLS, but again, should be a relatively rare concern.
> the people who know how to roll the firmware images probably don't even work there any more
Indeed another issue. But realistically, yes, IoT devices are going to have a finite lifetime if they depend on cloud services.