CVE-2025-15680 PUBLISHED

Information Disclosure via UART

Assigner: CyberDanube
Reserved: 04.08.2026 Published: 10.08.2026 Updated: 10.08.2026

TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.4

Product Status

Vendor TBEA
Product TBEA TLogger (TBEA Communication Box 3rd Generation)
Versions Default: unaffected
  • affected from 0 to V2.1.0.0B0.0.0.0 (incl.)

Credits

  • S. Eisenreich-Dietz (CyberDanube) finder
  • T. Weber (CyberDanube) finder
  • F. Koroknai finder
  • D. Blagojevic finder

References

Problem Types

  • CWE-497 CWE

Impacts

  • CAPEC-169 Footprinting