Executive brief
Teltonika Networks RUTOS and TSWOS devices, which are used in industrial and networking hardware, contain a security flaw in their profile management component. An attacker with existing low-level access to the device can exploit this flaw to gain full administrative (root) control. This could allow an unauthorized user to modify device configurations, intercept traffic, or disrupt network operations.
Technical details
An eval injection vulnerability (CWE-95) exists in the rpc-profile component of Teltonika Networks RUTOS (v7.22 - 7.23.2) and TSWOS (v1.09 - 1.09.1). The flaw stems from unsafe calls to an eval function, which fails to properly neutralize directives in dynamically evaluated code. A local attacker with high privileges (as per CVSS PR:H) or a lower-privileged user (as per the advisory text) can exploit this to perform command injection. Successful exploitation results in full system compromise with root-level execution. The vulnerability is addressed in the Teltonika Networks security center.
Affected products
- Teltonika Networks RUTOS 7.22 through 7.23.2
- Teltonika Networks TSWOS 1.09 through 1.09.1
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory