Impact
The vulnerability originates from an unsecured UART interface on the TBEA TLogger device. An attacker who can reach the board can attach a UART cable and read the serial output produced during boot and at runtime. The captured data reveal operating system details, software versions, network configuration, filesystem paths, and other debugging information that can aid further attacks. The flaw does not directly lead to code execution or denial of service, but the disclosed data may facilitate exploitation of other weaknesses.
Affected Systems
Systems affected are the TBEA TLogger V2.1.0.0B0.0.0.0, the third‑generation TBEA Communication Box. The issue is tied to this specific firmware revision and the presence of the exposed UART port.
Risk and Exploitability
The CVSS score of 2.4 indicates a low severity information exposure risk. Exploitation requires physical proximity to the UART port and the use of a serial cable; no public exploits or evidence of exploitation are documented. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a limited but non‑negligible risk for environments where the device is physically accessible to unauthorized persons.
OpenCVE Enrichment