CVE-2026-8914: Command injection in Profile change function
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Teltonika Networks RUTOSto a version that resolves this vulnerability.Fixed in 7.23.3 - Upgrade
Upgrade
Teltonika Networks TSWOSto a version that resolves this vulnerability.Fixed in 1.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8914?
CVE-2026-8914 has a high severity rating of 8.4 according to CVSS.
How do I fix CVE-2026-8914?
To fix CVE-2026-8914, update your RUTOS devices to version 7.23.3 or later, and TSWOS devices to version 1.10 or later.
What type of vulnerability is CVE-2026-8914?
CVE-2026-8914 is a command injection vulnerability affecting certain versions of Teltonika Networks RUTOS and TSWOS devices.
Who is affected by CVE-2026-8914?
CVE-2026-8914 affects Teltonika Networks RUTOS devices running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1.
What can attackers do with CVE-2026-8914?
An attacker with lower privileges could exploit CVE-2026-8914 to perform command injection as the root user.