CVE-2026-8914: high-severity vulnerability in Teltonika Networks RUTOS
Command injection in Profile change function
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.4epss 0.6%
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
nono source reports it
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Related CVEs — Teltonika Networks RUTOS
In the same product, most dangerous first.