CVE-2025-15680: Information Disclosure via UART
TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15680?
CVE-2025-15680 has a risk rating of 19, indicating a high severity vulnerability due to information disclosure.
How do I fix CVE-2025-15680?
To mitigate CVE-2025-15680, restrict physical access to the TBEA TLogger device and consider implementing additional security measures on the UART interface.
What type of information is disclosed in CVE-2025-15680?
CVE-2025-15680 can disclose sensitive information including operating system details and runtime debug output.
Who is affected by CVE-2025-15680?
CVE-2025-15680 affects users of TBEA TLogger version 2.1.0.0B0.0.0.0 with an exposed UART interface.
Is a workaround available for CVE-2025-15680?
Currently, there is no official workaround for CVE-2025-15680 other than limiting physical access to the device.