AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2025-15681

CRITICAL · CVSS 9.2 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The TBEA TLogger V2.1.0.0B0.0.0.0 is vulnerable to an authentication bypass in its web server, allowing unauthenticated attackers to access protected functionalities via the /index.asp endpoint after a user has logged in. This critical vulnerability could lead to unauthorized access to sensitive device configurations and data, as well as potential denial-of-service conditions due to server crashes upon logout. Organizations using this device should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2025-15681
Severity
CRITICAL
CVSS
9.2
EPSS
0.48%

Original NVD Description

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid credentials. This allows the attacker to access functionality intended for authenticated users and may expose or modify device configuration and data. Logging out from the bypassed state can additionally cause the web server to crash.