An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated attacker can exploit these endpoints to read, modify, or delete data stored in the device's CCU.db database.
References
History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tbea
Tbea tbea Tlogger
Vendors & Products Tbea
Tbea tbea Tlogger

Mon, 10 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated attacker can exploit these endpoints to read, modify, or delete data stored in the device's CCU.db database.
Title Unauthenticated SQL Injection
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published: 2026-08-10T19:25:32.123Z

Updated: 2026-08-10T19:25:32.123Z

Reserved: 2025-11-17T11:17:18.796Z

Link: CVE-2025-13294

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-10T20:17:24.583

Modified: 2026-08-10T20:17:24.583

Link: CVE-2025-13294

cve-icon Redhat

No data.