CVE-2024-8256: Incorrect Permission Assignment in RutOS based routers and TSWOS based managed switches
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8256?
CVE-2024-8256 has a medium severity rating due to the potential for unauthorized access to critical systems.
How do I fix CVE-2024-8256?
To fix CVE-2024-8256, update your Teltonika Networks RUTOS devices to version 7.9 or later, and TSWOS devices to version 1.4 or later.
Which devices are affected by CVE-2024-8256?
CVE-2024-8256 affects Teltonika Networks RUTOS devices running versions 7.0 to 7.8 and TSWOS devices running versions 1.0 to 1.3.
What type of vulnerability is CVE-2024-8256?
CVE-2024-8256 is a permission handling vulnerability that allows lower privileged users to access critical data.
Is there a workaround for CVE-2024-8256?
There is no official workaround for CVE-2024-8256, updating to the latest software version is the recommended action.