In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update to RUTOS 7.23.3 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.teltonika-networks.com/support/security-centre |
|
History
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user. | |
| Title | Command injection in Profile change function | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tlt_net
Published:
Updated: 2026-06-05T20:21:59.678Z
Reserved: 2026-05-19T05:45:27.190Z
Link: CVE-2026-8914
No data.
Status : Awaiting Analysis
Published: 2026-06-05T11:16:37.043
Modified: 2026-06-05T14:59:51.620
Link: CVE-2026-8914
No data.
OpenCVE Enrichment
Updated: 2026-06-05T11:30:39Z
Weaknesses