Unauthenticated Remote Denial-of-Service Vulnerability in TBEA TLogger by TBEA
CVE-2025-15683

8.8HIGH

Key Information:

Vendor

Tbea

Vendor
CVE Published:
10 August 2026

What is CVE-2025-15683?

TBEA TLogger version 2.1.0.0B0.0.0.0 exhibits multiple vulnerabilities that allow unauthenticated attackers to disrupt web server operation. By exploiting specific HTTP endpoints, an attacker can trigger device reboots, reset the device, clear application data, or cause the web server to crash due to segmentation faults. Additionally, many action endpoints improperly handle user-supplied input when performing string operations, leading to potential buffer overflow conditions. The affected endpoints include crucial functions such as onRestart, onReset, and ClearData, among others. Proper risk mitigation strategies should be implemented to safeguard against these security weaknesses.

Affected Version(s)

TBEA TLogger (TBEA Communication Box 3rd Generation) 0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

S. Eisenreich-Dietz (CyberDanube)
T. Weber (CyberDanube)
F. Koroknai
D. Blagojevic
.