๐Ÿ” CVE Alert

CVE-2025-15682

UNKNOWN 0.0

Unauthenticated Resource Exhaustion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/ endpoint, causing the web server to create persistent files containing attacker-controlled data under /opt/myapp/webserver/. The generated files are not removed because the web server attempts to move them into a non-existent directory. Repeated requests can therefore exhaust available storage and cause a denial-of-service condition.

CWE CWE-770
Vendor tbea
Product tbea tlogger (tbea communication box 3rd generation)
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for tbea tbea tlogger (tbea communication box 3rd generation)

Be the first to know when new unknown vulnerabilities affecting tbea tbea tlogger (tbea communication box 3rd generation) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TBEA / TBEA TLogger (TBEA Communication Box 3rd Generation)
0 โ‰ค V2.1.0.0B0.0.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
en.tbea.com: https://en.tbea.com/about.html

Credits

S. Eisenreich-Dietz (CyberDanube) T. Weber (CyberDanube) F. Koroknai D. Blagojevic