PT-2026-69928 · Tbea · Tlogger
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TBEA TLogger version 2.1.0.0B0.0.0.0
Description
The web server contains an authentication bypass. If a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality via the '/index.asp' endpoint without valid credentials. This allows unauthorized access to features intended for authenticated users, potentially exposing or modifying device configuration and data. Additionally, logging out while in this bypassed state can cause the web server to crash.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tlogger