CVE-2026-14960

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O port reads and writes without authorization checks. A local attacker can abuse this functionality to manipulate hardware registers, tamper with firmware-related interfaces, cause system instability, or establish persistent low-level compromise.
References
Configurations

No configuration.

History

16 Jul 2026, 16:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-284
CWE-269
CWE-668

15 Jul 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 18:16

Updated : 2026-07-16 16:19


NVD link : CVE-2026-14960

Mitre link : CVE-2026-14960

CVE.ORG link : CVE-2026-14960


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management

CWE-284

Improper Access Control

CWE-668

Exposure of Resource to Wrong Sphere