CVE-2025-15682
Unauthenticated Resource Exhaustion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/ endpoint, causing the web server to create persistent files containing attacker-controlled data under /opt/myapp/webserver/. The generated files are not removed because the web server attempts to move them into a non-existent directory. Repeated requests can therefore exhaust available storage and cause a denial-of-service condition.
| CWE | CWE-770 |
| Vendor | tbea |
| Product | tbea tlogger (tbea communication box 3rd generation) |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for tbea tbea tlogger (tbea communication box 3rd generation)
Be the first to know when new unknown vulnerabilities affecting tbea tbea tlogger (tbea communication box 3rd generation) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TBEA / TBEA TLogger (TBEA Communication Box 3rd Generation)
0 โค V2.1.0.0B0.0.0.0
Credits
S. Eisenreich-Dietz (CyberDanube) T. Weber (CyberDanube) F. Koroknai D. Blagojevic