CVE-2026-16455 PUBLISHED

Local privilege escalation via improper input sanitization in execl() call

Assigner: tlt_net
Reserved: 21.07.2026 Published: 13.08.2026 Updated: 13.08.2026

In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Teltonika Networks
Product RUTOS
Versions Default: unaffected
  • affected from RUTOS 7.07.1 to 7.24.1 (incl.)
Vendor Teltonika Networks
Product TSWOS
Versions Default: unaffected
  • affected from 1.03 to 1.10 (incl.)

Solutions

Update to RUTOS 7.24.2 or later.

Update to TSWOS 1.10.1 or later.

References

Problem Types

  • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') CWE

Impacts

  • CAPEC-233: Privilege Escalation