Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-14960: Pegatron Tdelo64.sys Privileged Hardware Access Exposure

CVE-2026-14960 CVE-2026-14960
Summary

A security issue affects Pegatron's Tdelo64.sys driver, which allows unauthorized access to sensitive hardware features. This could be exploited by an attacker on the same local network, potentially causing system crashes or allowing long-term control over the system. To mitigate this, update to the latest version of the driver or disable the TdeIo device interface if not required.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
pegatron corp. tdelo64.sys <= 02-17-2025
Original title
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO...
Original description
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O port reads and writes without authorization checks. A local attacker can abuse this functionality to manipulate hardware registers, tamper with firmware-related interfaces, cause system instability, or establish persistent low-level compromise.
Vulnerability type
CWE-284 Improper Access Control
CWE-668
CWE-269 Improper Privilege Management
Published: 15 Jul 2026 · Updated: 17 Jul 2026 · First seen: 15 Jul 2026