Impact
A lower‑privileged user can gain administrative privileges on unsupported Teltonika RUTOS and TSWOS firmware by exploiting an unsafe execl call that fails to sanitize input. The flaw is local, requiring the attacker to execute commands on the device where the vulnerable binary runs. Recipients of the privilege boost can modify system configuration, install software, or access sensitive network traffic, thereby compromising confidentiality, integrity, and availability of the device.
Affected Systems
Teltonika Networks RUTOS firmware versions 7.07.1 to 7.24.1 and TSWOS firmware versions 1.03 to 1.10 are affected; newer firmware releases are not impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. No EPSS value is provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of active exploitation. However, because the attack vector is local and attackers can add themselves to privileged groups or alter configuration files, the risk remains significant for organizations that rely on default device access controls. Exploitation requires a user present on the device, so preventing local boot or read/write access through proper physical security also mitigates the vulnerability.
OpenCVE Enrichment