CVE-2024-8256
MEDIUMTeltonika Networks RUTOS <7.8, TSWOS <1.3 - Privilege Escalation
Title source: llmDescription
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API.
References (1)
Core 1
Core References
Various Sources third-party-advisory
https://www.deepcove.support/teltonika-responsible-disclosure-proactive-testing-report/
Scores
CVSS v4
5.9
EPSS
0.0019
EPSS Percentile
8.6%
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-732
Status
published
Products (2)
Teltonika Networks/RUTOS
7.0 - 7.8
Teltonika Networks/TSWOS
1.0 - 1.3
Published
Dec 10, 2024
Tracked Since
Feb 18, 2026