CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated remote attackers to gain root-level access to TBEA TLogger V2.1.0.0B0.0.0.0 due to hard-coded or default credentials, which can be extracted from the password hash in the /etc/shadow file. This critical flaw enables full administrative control over the device through the exposed SSH service, posing significant risks to system integrity and confidentiality. Organizations using this version of TLogger should prioritize immediate remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device.