CVE-2025-15683: Multiple Unauthenticated Denial-of-Service Conditions
TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or reset the device, clear application data, or terminate the web server through a segmentation fault. In addition, multiple action endpoints process attacker-controlled parameters using unsafe string operations such as sprintf() and strcat() without adequate bounds checking, allowing crafted input to trigger buffer overflows and crash the web server. The affected endpoints include onRestart, onReset, ClearData, uploadInvFile, getIndiaRPData, YearCaparity, TotalfaultData, recordData, InvHistoryData, CollectHistoryData, InvFaultData, GetPortTableByParm, and UpdatePortConfig.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15683?
CVE-2025-15683 is rated with a risk score of 42, indicating it poses significant threats.
How do I fix CVE-2025-15683?
To mitigate CVE-2025-15683, apply updates provided by TBEA or disable external access to the TLogger web server.
What vulnerabilities are associated with CVE-2025-15683?
CVE-2025-15683 encompasses multiple unauthenticated denial-of-service vulnerabilities that can affect the TBEA TLogger web server.
Can CVE-2025-15683 be exploited remotely?
Yes, an unauthenticated remote attacker can exploit CVE-2025-15683 by targeting specific HTTP endpoints.
What potential impact does CVE-2025-15683 have?
CVE-2025-15683 can lead to device reboot, application data loss, or web server termination through segmentation faults.