CVE-2025-15681 PUBLISHED

Insufficient Webserver Authentication

Assigner: CyberDanube
Reserved: 04.08.2026 Published: 10.08.2026 Updated: 10.08.2026

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid credentials. This allows the attacker to access functionality intended for authenticated users and may expose or modify device configuration and data. Logging out from the bypassed state can additionally cause the web server to crash.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor TBEA
Product TBEA TLogger (TBEA Communication Box 3rd Generation)
Versions Default: unaffected
  • affected from 0 to V2.1.0.0B0.0.0.0 (incl.)

Credits

  • S. Eisenreich-Dietz (CyberDanube) finder
  • T. Weber (CyberDanube) finder
  • F. Koroknai finder
  • D. Blagojevic finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • CAPEC-115 Authentication Bypass