Vulnerability Description
TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid credentials. This allows the attacker to access functionality intended for authenticated users and may expose or modify device configuration and data. Logging out from the bypassed state can additionally cause the web server to crash.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-15681?
CVE-2025-15681 is a documented vulnerability. TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected fu...
How severe is CVE-2025-15681?
CVSS scoring is not yet available for CVE-2025-15681. Check NVD for updates.
Is there a patch for CVE-2025-15681?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.