Impact
The vulnerability is an unauthenticated SQL injection in the web server of TBEA TLogger. It allows an attacker to inject SQL into SQLite queries that run on the device’s CCU.db database, enabling the attacker to read, modify, or delete stored data. This flaw is a classic input validation failure (CWE‑89). The high CVSS score of 9.3 reflects the potential for widespread data compromise and integrity loss even when the attacker needs no credentials.
Affected Systems
The affected product is the TBEA TLogger Version V2.1.0.0B0.0.0.0, part of the TBEA Communication Box 3rd Generation line. The flaw resides in multiple HTTP endpoints exposed by the device’s web server and can be leveraged by external parties facing the device.
Risk and Exploitability
The attack vector is inferred to be remote over HTTP, as the flaw is accessed via web endpoints and requires no authentication. With a CVSS score of 9.3, the risk is considered critical, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, leaving the likelihood of widespread exploitation uncertain. Nevertheless, the lack of authentication and direct database manipulation capabilities make this a severe vulnerability for any organization deploying the vulnerable firmware.
OpenCVE Enrichment