PT-2026-69928 · Tbea · Tlogger

·

CVE-2025-15681

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TBEA TLogger version 2.1.0.0B0.0.0.0
Description The web server contains an authentication bypass. If a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality via the '/index.asp' endpoint without valid credentials. This allows unauthorized access to features intended for authenticated users, potentially exposing or modifying device configuration and data. Additionally, logging out while in this bypassed state can cause the web server to crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15681

Affected Products

Tlogger