PatchSiren

Teltonika Networks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Teltonika Networks CVE published 2026-08-13

CVE-2026-18368

CVE-2026-18368 debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T11:17:38.497Z and has not been modified since then. This vulnerability affects Teltonika Networks RUTOS devices, specifically the modbusgwd service, and could lead to a denial of service via a heap-based buffer overflow. Defenders should verify exposure and assess potential mitigations. The modbusgwd ser [truncated]

MEDIUM Teltonika Networks CVE published 2026-08-13

CVE-2026-16455

A vulnerability exists in Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function. This issue has a CVSS score of 6.9 and is classified as MEDIUM severity. The vulnerability allows for privilege escalation, which can [truncated]

HIGH Teltonika Networks CVE published 2026-06-05

CVE-2026-8914

A high-severity command injection vulnerability exists in Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2, and TSWOS devices, running versions 1.09 through 1.09.1. The vulnerability is caused by unsafe calls to an eval function in rpc-profile, allowing a lower privileged user to perform command injection as the root user. The Common Vulnerability Scoring System (CVSS) score for this [truncated]