A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://en.tbea.com/about.html |
|
History
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tbea
Tbea tbea Tlogger |
|
| Vendors & Products |
Tbea
Tbea tbea Tlogger |
Mon, 10 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device. | |
| Title | Backdoor / default root credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CyberDanube
Published:
Updated: 2026-08-10T19:24:10.104Z
Reserved: 2025-11-17T11:17:17.483Z
Link: CVE-2025-13293
No data.
Status : Received
Published: 2026-08-10T20:17:23.493
Modified: 2026-08-10T20:17:23.493
Link: CVE-2025-13293
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:22:07Z
Weaknesses