CVE-2025-15683: Multiple Unauthenticated Denial-of-Service Conditions

Published Aug 10, 2026
·
Updated

TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or reset the device, clear application data, or terminate the web server through a segmentation fault. In addition, multiple action endpoints process attacker-controlled parameters using unsafe string operations such as sprintf() and strcat() without adequate bounds checking, allowing crafted input to trigger buffer overflows and crash the web server. The affected endpoints include onRestart, onReset, ClearData, uploadInvFile, getIndiaRPData, YearCaparity, TotalfaultData, recordData, InvHistoryData, CollectHistoryData, InvFaultData, GetPortTableByParm, and UpdatePortConfig.

Affected Software

1 affected component
TBEA TLogger V2.1.0.0B0.0.0.0=2.1.0.0B0.0.0.0

Event History

Aug 10, 2026
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-15683?

CVE-2025-15683 is rated with a risk score of 42, indicating it poses significant threats.

2

How do I fix CVE-2025-15683?

To mitigate CVE-2025-15683, apply updates provided by TBEA or disable external access to the TLogger web server.

3

What vulnerabilities are associated with CVE-2025-15683?

CVE-2025-15683 encompasses multiple unauthenticated denial-of-service vulnerabilities that can affect the TBEA TLogger web server.

4

Can CVE-2025-15683 be exploited remotely?

Yes, an unauthenticated remote attacker can exploit CVE-2025-15683 by targeting specific HTTP endpoints.

5

What potential impact does CVE-2025-15683 have?

CVE-2025-15683 can lead to device reboot, application data loss, or web server termination through segmentation faults.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203