CVE-2026-16455: Local privilege escalation via improper input sanitization in execl() call
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Teltonika Networks RUTOSto a version that resolves this vulnerability.Fixed in 7.24.2 - Upgrade
Upgrade
Teltonika Networks TSWOSto a version that resolves this vulnerability.Fixed in 1.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16455?
CVE-2026-16455 has a risk level of 49, indicating it poses a significant security threat.
How do I fix CVE-2026-16455?
To fix CVE-2026-16455, update your Teltonika Networks RUTOS devices to version 7.24.2 or later, and TSWOS devices to version 1.11 or later.
Who is affected by CVE-2026-16455?
CVE-2026-16455 affects Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10.
What type of vulnerability is CVE-2026-16455?
CVE-2026-16455 is classified as a local privilege escalation vulnerability caused by improper input sanitization in an execl() call.
What are the consequences of CVE-2026-16455?
The consequences of CVE-2026-16455 include the potential for a lower privileged user to escalate their privileges to an administrative level.