Unauthenticated Remote Denial-of-Service Vulnerability in TBEA TLogger by TBEA
CVE-2025-15683
What is CVE-2025-15683?
TBEA TLogger version 2.1.0.0B0.0.0.0 exhibits multiple vulnerabilities that allow unauthenticated attackers to disrupt web server operation. By exploiting specific HTTP endpoints, an attacker can trigger device reboots, reset the device, clear application data, or cause the web server to crash due to segmentation faults. Additionally, many action endpoints improperly handle user-supplied input when performing string operations, leading to potential buffer overflow conditions. The affected endpoints include crucial functions such as onRestart, onReset, and ClearData, among others. Proper risk mitigation strategies should be implemented to safeguard against these security weaknesses.
Affected Version(s)
TBEA TLogger (TBEA Communication Box 3rd Generation) 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
