CVE-2026-8914: Teltonika Networks Rutos

High severity, CVSS 8.4. EPSS: 0.6% chance of exploitation in the next 30 days.

In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.

Affected products

Published 2026-06-05. Last modified 2026-06-17.