PT-2026-69925 · Tbea · Tlogger
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
TBEA TLogger version 2.1.0.0B0.0.0.0
Description
A hard-coded or default root account credential allows an unauthenticated remote attacker to gain root-level access to the device through the exposed SSH service. The root password can be retrieved from the password hash located in the
/etc/shadow file and used to authenticate via SSH, granting full administrative control of the device.Recommendations
For version 2.1.0.0B0.0.0.0, change the default root account credentials to a strong, unique password.
Restrict access to the SSH service to authorized users and networks only.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tlogger