Home
HIGH: 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
7.22 (custom)
affected
Default status
unaffected
1.09 (custom)
affected
Description
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.
Problem types
CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection')
Product status
7.22 (custom)
1.09 (custom)
References
www.teltonika-networks.com/support/security-centre