Description
A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device.
Published: 2026-08-10
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A hard‑coded or default root credential stored in the device allows an unauthenticated attacker to recover the root password from /etc/shadow and authenticate to the exposed SSH service. Once authenticated, the attacker gains full administrative control, enabling any modification or data exfiltration. This breach compromises confidentiality, integrity, and availability of the device and any services it manages.

Affected Systems

TBEA TLogger V2.1.0.0B0.0.0.0, a third‑generation TBEA Communication Box, is affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3, indicating critical severity. No KEV listing or EPSS score is available, but the nature of default credentials combined with an exposed ssh interface renders exploitation highly probable for remote attackers with no prior authentication. Attackers can obtain the root password directly from the device and then log in to SSH without any additional foothold.

Generated by OpenCVE AI on August 10, 2026 at 20:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware upgrade that eliminates the hard‑coded root credential.
  • If an upgrade is not available, disable the SSH service or limit SSH access to trusted IP addresses only.
  • After executing the upgrade or tightening SSH access, set a unique, strong root password and store it securely.

Generated by OpenCVE AI on August 10, 2026 at 20:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 10 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device.
Title Backdoor / default root credentials
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-08-10T19:24:10.104Z

Reserved: 2025-11-17T11:17:17.483Z

Link: CVE-2025-13293

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T20:45:05Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials