PT-2026-69925 · Tbea · Tlogger

·

CVE-2025-13293

·

Published

2026-08-10

·

Updated

2026-08-12

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions TBEA TLogger version 2.1.0.0B0.0.0.0
Description A hard-coded or default root account credential allows an unauthenticated remote attacker to gain root-level access to the device through the exposed SSH service. The root password can be retrieved from the password hash located in the /etc/shadow file and used to authenticate via SSH, granting full administrative control of the device.
Recommendations For version 2.1.0.0B0.0.0.0, change the default root account credentials to a strong, unique password. Restrict access to the SSH service to authorized users and networks only.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13293

Affected Products

Tlogger