VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys

2026-07-15T20:52:19Z9ab484d069b8076e029a8240fed20e8ee821a44680a53ecf5fa4ba01755aa1d4
ASN.1AdaloAndroidEd25519FTP PASVGNU WgetIOCTLJWT reuse','CORS','Tenda','firmware backdoor','router','IoTJavaScript injectionPayRangePegatronRCERSA-PKCS1-v1_5SSRFTLS validationWebViewXerte Online Toolkitauthentication bypasscryptographydata exposurekernelnode-forgeprivilege escalationsignature forgerytdeio64.sys

What happened

CERT/CC published multiple vulnerability advisories affecting a range of software and devices. Key issues include: a Pegatron tdeio64.sys Windows driver that exposes unprotected IOCTLs enabling arbitrary kernel read/write and local privilege escalation to NT AUTHORITY\SYSTEM (CVE-2026-14961, CVE-2026-14960); node-forge signature verification flaws allowing RSA-PKCS#1 v1.5 and Ed25519 signature forgeries (CVE-2026-33894, CVE-2026-33895); an FTP PASV IP validation flaw in GNU Wget enabling SSRF (CVE-2026-15146); PayRange Android app WebView TLS/JS handling that accepts invalid certificates and允许

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
9ab484d069b8076e029a8240fed20e8ee821a44680a53ecf5fa4ba01755aa1d4
Enrichment time
2026-07-15T20:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys · Baitaphish