TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid credentials. This allows the attacker to access functionality intended for authenticated users and may expose or modify device configuration and data. Logging out from the bypassed state can additionally cause the web server to crash.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://en.tbea.com/about.html |
|
History
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tbea
Tbea tbea Tlogger |
|
| Vendors & Products |
Tbea
Tbea tbea Tlogger |
Mon, 10 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid credentials. This allows the attacker to access functionality intended for authenticated users and may expose or modify device configuration and data. Logging out from the bypassed state can additionally cause the web server to crash. | |
| Title | Insufficient Webserver Authentication | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CyberDanube
Published: 2026-08-10T19:31:05.467Z
Updated: 2026-08-12T18:13:49.621Z
Reserved: 2026-08-04T11:34:47.562Z
Link: CVE-2025-15681
Updated: 2026-08-12T18:13:43.955Z
Status : Received
Published: 2026-08-10T20:17:25.157
Modified: 2026-08-12T19:17:28.390
Link: CVE-2025-15681
No data.