Impact
A hard‑coded or default root credential stored in the device allows an unauthenticated attacker to recover the root password from /etc/shadow and authenticate to the exposed SSH service. Once authenticated, the attacker gains full administrative control, enabling any modification or data exfiltration. This breach compromises confidentiality, integrity, and availability of the device and any services it manages.
Affected Systems
TBEA TLogger V2.1.0.0B0.0.0.0, a third‑generation TBEA Communication Box, is affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating critical severity. No KEV listing or EPSS score is available, but the nature of default credentials combined with an exposed ssh interface renders exploitation highly probable for remote attackers with no prior authentication. Attackers can obtain the root password directly from the device and then log in to SSH without any additional foothold.
OpenCVE Enrichment