CVE-2025-15681: Insufficient Webserver Authentication
TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid credentials. This allows the attacker to access functionality intended for authenticated users and may expose or modify device configuration and data. Logging out from the bypassed state can additionally cause the web server to crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TBEA TLoggerto a version that resolves this vulnerability.Fixed in 2.1.0.0B0.0.0.0 - Compensating control
Immediately restrict network access to the device/web server endpoints that include /index.asp (e.g., via firewall/ACL/WAF) to reduce exposure to unauthenticated requests.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15681?
The severity of CVE-2025-15681 is rated at 62.
How do I fix CVE-2025-15681?
To mitigate CVE-2025-15681, ensure that your TLogger is updated to a patched version that addresses the authentication bypass vulnerability.
What vulnerabilities are associated with CVE-2025-15681?
CVE-2025-15681 is associated with an authentication bypass that could allow unauthorized access to protected functionalities.
Who is affected by CVE-2025-15681?
Users of TBEA TLogger V2.1.0.0B0.0.0.0 are affected by CVE-2025-15681.
When was CVE-2025-15681 published?
CVE-2025-15681 was published on August 10, 2026.