VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys
2026-07-15T20:52:19Z•9ab484d069b8076e029a8240fed20e8ee821a44680a53ecf5fa4ba01755aa1d4
ASN.1AdaloAndroidEd25519FTP PASVGNU WgetIOCTLJWT reuse','CORS','Tenda','firmware backdoor','router','IoTJavaScript injectionPayRangePegatronRCERSA-PKCS1-v1_5SSRFTLS validationWebViewXerte Online Toolkitauthentication bypasscryptographydata exposurekernelnode-forgeprivilege escalationsignature forgerytdeio64.sys
What happened
CERT/CC published multiple vulnerability advisories affecting a range of software and devices. Key issues include: a Pegatron tdeio64.sys Windows driver that exposes unprotected IOCTLs enabling arbitrary kernel read/write and local privilege escalation to NT AUTHORITY\SYSTEM (CVE-2026-14961, CVE-2026-14960); node-forge signature verification flaws allowing RSA-PKCS#1 v1.5 and Ed25519 signature forgeries (CVE-2026-33894, CVE-2026-33895); an FTP PASV IP validation flaw in GNU Wget enabling SSRF (CVE-2026-15146); PayRange Android app WebView TLS/JS handling that accepts invalid certificates and允许
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 9ab484d069b8076e029a8240fed20e8ee821a44680a53ecf5fa4ba01755aa1d4
- Enrichment time
- 2026-07-15T20:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.