CVE-2026-8914: Teltonika Networks Rutos
High severity, CVSS 8.4. EPSS: 0.6% chance of exploitation in the next 30 days.
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.
Affected products
- Teltonika Networks Rutos: from 7.22, up to and including 7.23.2
- Teltonika Networks Tswos: from 1.09, up to and including 1.09.1
Published 2026-06-05. Last modified 2026-06-17.