Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-14960: Pegatron Tdelo64.sys Privileged Hardware Access Exposure
CVE-2026-14960
CVE-2026-14960
Summary
A security issue affects Pegatron's Tdelo64.sys driver, which allows unauthorized access to sensitive hardware features. This could be exploited by an attacker on the same local network, potentially causing system crashes or allowing long-term control over the system. To mitigate this, update to the latest version of the driver or disable the TdeIo device interface if not required.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| pegatron corp. | tdelo64.sys | <= 02-17-2025 |
Original title
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO...
Original description
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O port reads and writes without authorization checks. A local attacker can abuse this functionality to manipulate hardware registers, tamper with firmware-related interfaces, cause system instability, or establish persistent low-level compromise.
Vulnerability type
CWE-284
Improper Access Control
CWE-668
CWE-269
Improper Privilege Management
Published: 15 Jul 2026 · Updated: 17 Jul 2026 · First seen: 15 Jul 2026