Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://en.tbea.com/about.html |
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tbea
Tbea tbea Tlogger |
|
| Vendors & Products |
Tbea
Tbea tbea Tlogger |
Mon, 10 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or reset the device, clear application data, or terminate the web server through a segmentation fault. In addition, multiple action endpoints process attacker-controlled parameters using unsafe string operations such as sprintf() and strcat() without adequate bounds checking, allowing crafted input to trigger buffer overflows and crash the web server. The affected endpoints include onRestart, onReset, ClearData, uploadInvFile, getIndiaRPData, YearCaparity, TotalfaultData, recordData, InvHistoryData, CollectHistoryData, InvFaultData, GetPortTableByParm, and UpdatePortConfig. | |
| Title | Multiple Unauthenticated Denial-of-Service Conditions | |
| Weaknesses | CWE-121 CWE-306 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CyberDanube
Published:
Updated: 2026-08-10T19:38:57.641Z
Reserved: 2026-08-04T11:34:49.423Z
Link: CVE-2025-15683
No data.
Status : Received
Published: 2026-08-10T20:17:25.420
Modified: 2026-08-10T20:17:25.420
Link: CVE-2025-15683
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:21:53Z