CVE-2025-13293: Backdoor / default root credentials
A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13293?
CVE-2025-13293 has a severity score of 95, indicating a critical risk.
How do I fix CVE-2025-13293?
To fix CVE-2025-13293, it is essential to change the default root credentials and disable the exposed SSH service.
What type of access does CVE-2025-13293 allow?
CVE-2025-13293 allows unauthenticated remote attackers to obtain root-level access to the device.
Which software is affected by CVE-2025-13293?
CVE-2025-13293 affects the TBEA TLogger version 2.1.0.0B0.0.0.0.
What vulnerability does CVE-2025-13293 exploit?
CVE-2025-13293 exploits hard-coded or default root account credentials in the TBEA TLogger.