CVE-2026-16455

Summary

In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.

Affected Software

VendorProductVersion RangeStatus
Teltonika NetworksRUTOSRUTOS 7.07.1 <= 7.24.1affected
Teltonika NetworksTSWOS1.03 <= 1.10affected

Weaknesses

  • CWE-93: CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References