Description
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.
Published: 2026-08-13
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A lower‑privileged user can gain administrative privileges on unsupported Teltonika RUTOS and TSWOS firmware by exploiting an unsafe execl call that fails to sanitize input. The flaw is local, requiring the attacker to execute commands on the device where the vulnerable binary runs. Recipients of the privilege boost can modify system configuration, install software, or access sensitive network traffic, thereby compromising confidentiality, integrity, and availability of the device.

Affected Systems

Teltonika Networks RUTOS firmware versions 7.07.1 to 7.24.1 and TSWOS firmware versions 1.03 to 1.10 are affected; newer firmware releases are not impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. No EPSS value is provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of active exploitation. However, because the attack vector is local and attackers can add themselves to privileged groups or alter configuration files, the risk remains significant for organizations that rely on default device access controls. Exploitation requires a user present on the device, so preventing local boot or read/write access through proper physical security also mitigates the vulnerability.

Generated by OpenCVE AI on August 13, 2026 at 12:50 UTC.

Remediation

Vendor Solution

Update to RUTOS 7.24.2 or later. Update to TSWOS 1.10.1 or later.


OpenCVE Recommended Actions

  • Update RUTOS firmware to 7.24.2 or later
  • Update TSWOS firmware to 1.10.1 or later
  • Restrict local user accounts to the minimum necessary privileges and audit for unexpected changes to system binaries

Generated by OpenCVE AI on August 13, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Teltonika-networks
Teltonika-networks rutos
Teltonika-networks tswos
Vendors & Products Teltonika-networks
Teltonika-networks rutos
Teltonika-networks tswos

Thu, 13 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.
Title Local privilege escalation via improper input sanitization in execl() call
Weaknesses CWE-93
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Teltonika-networks Rutos Tswos
cve-icon MITRE

Status: PUBLISHED

Assigner: tlt_net

Published:

Updated: 2026-08-13T14:45:18.394Z

Reserved: 2026-07-21T10:10:50.437Z

Link: CVE-2026-16455

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T11:17:38.340

Modified: 2026-08-13T15:19:33.700

Link: CVE-2026-16455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:00:04Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')