Description
TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device.
Published: 2026-08-10
Score: 2.4 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from an unsecured UART interface on the TBEA TLogger device. An attacker who can reach the board can attach a UART cable and read the serial output produced during boot and at runtime. The captured data reveal operating system details, software versions, network configuration, filesystem paths, and other debugging information that can aid further attacks. The flaw does not directly lead to code execution or denial of service, but the disclosed data may facilitate exploitation of other weaknesses.

Affected Systems

Systems affected are the TBEA TLogger V2.1.0.0B0.0.0.0, the third‑generation TBEA Communication Box. The issue is tied to this specific firmware revision and the presence of the exposed UART port.

Risk and Exploitability

The CVSS score of 2.4 indicates a low severity information exposure risk. Exploitation requires physical proximity to the UART port and the use of a serial cable; no public exploits or evidence of exploitation are documented. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a limited but non‑negligible risk for environments where the device is physically accessible to unauthorized persons.

Generated by OpenCVE AI on August 10, 2026 at 20:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TBEA that secures the UART interface or disables debug output; check the vendor’s website for a patch.
  • If a patch is unavailable, physically disconnect or cover the UART connector to prevent unauthorized hardware access.
  • Ensure the device is placed in a locked enclosure and enforce strict physical access controls to limit proximity to the UART port.

Generated by OpenCVE AI on August 10, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 10 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device.
Title Information Disclosure via UART
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-08-10T19:27:28.958Z

Reserved: 2026-08-04T11:34:46.057Z

Link: CVE-2025-15680

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T20:45:05Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere