CVE-2024-8256

MEDIUM

Teltonika Networks RUTOS <7.8, TSWOS <1.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API.

References (1)

Core 1

Scores

CVSS v4 5.9
EPSS 0.0019
EPSS Percentile 8.6%
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (2)
Teltonika Networks/RUTOS 7.0 - 7.8
Teltonika Networks/TSWOS 1.0 - 1.3
Published Dec 10, 2024
Tracked Since Feb 18, 2026