Executive brief
Teltonika RUTOS and TSWOS are routing and switching operating systems used in industrial IoT and edge networking environments. A lower-privileged user can escalate to administrative privileges due to unsafe function calls, allowing a local attacker with basic user access to take complete control of the device and its network operations.
Technical details
This vulnerability is a local privilege escalation flaw caused by unsafe calls to the execl function in Teltonika RUTOS (versions 7.07.1 through 7.24.1) and TSWOS (versions 1.03 through 1.10). The vulnerability allows a lower-privileged user to escalate privileges to the administrative level. An attacker with local user access can exploit this to achieve root-level code execution. The attack vector is local, requiring existing user-level access to the device. Patches are expected to be available from Teltonika Networks.
Affected products
- Teltonika Networks RUTOS 7.07.1 through 7.24.1
- Teltonika Networks TSWOS 1.03 through 1.10
Timeline
- 2026-08-13: disclosed