Junglewise Threat Intelligence

CVE-2026-8914: Teltonika Networks RUTOS and TSWOS command injection in rpc-profile

CVE-2026-8914 · Severity: info · CVSS 8.4 · Published 2026-06-05

Technologies: Teltonika Networks RUTOS. Vendors: Teltonika Networks.

Executive brief

Teltonika Networks RUTOS and TSWOS devices, which are used in industrial and networking hardware, contain a security flaw in their profile management component. An attacker with existing low-level access to the device can exploit this flaw to gain full administrative (root) control. This could allow an unauthorized user to modify device configurations, intercept traffic, or disrupt network operations.

Technical details

An eval injection vulnerability (CWE-95) exists in the rpc-profile component of Teltonika Networks RUTOS (v7.22 - 7.23.2) and TSWOS (v1.09 - 1.09.1). The flaw stems from unsafe calls to an eval function, which fails to properly neutralize directives in dynamically evaluated code. A local attacker with high privileges (as per CVSS PR:H) or a lower-privileged user (as per the advisory text) can exploit this to perform command injection. Successful exploitation results in full system compromise with root-level execution. The vulnerability is addressed in the Teltonika Networks security center.

Affected products

  • Teltonika Networks RUTOS 7.22 through 7.23.2
  • Teltonika Networks TSWOS 1.09 through 1.09.1

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats