PatchSiren

Teltonika Networks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Teltonika Networks CVE published 2026-06-05

CVE-2026-8914

A high-severity command injection vulnerability exists in Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2, and TSWOS devices, running versions 1.09 through 1.09.1. The vulnerability is caused by unsafe calls to an eval function in rpc-profile, allowing a lower privileged user to perform command injection as the root user. The Common Vulnerability Scoring System (CVSS) score for this [truncated]