Impact
The vulnerability resides in the web server of TBEA TLogger version 2.1.0.0B0.0.0.0. An authentication bypass allows an attacker who has already logged into the device to request the /index.asp endpoint without valid credentials. This flaw permits access to functions that should be restricted to authenticated users, exposing or altering device configuration and stored data. The weakness is a CWE-306, an Authentication Bypass.
Affected Systems
The affected product is TBEA TLogger 2.1.0.0B0.0.0.0, the third‑generation TBEA Communication Box. No other versions are listed as impacted in the CVE data.
Risk and Exploitability
With a CVSS score of 9.2, this flaw presents a high‑severity risk. The vulnerability does not necessitate special exploitation conditions beyond an initial authenticated session, meaning that once an attacker can reach the device, they can readily access protected resources via the /index.asp endpoint. The EPSS score is not available, but the severity level indicates exploitation is likely if the device is exposed. Although the flaw is not listed in the CISA KEV catalog, the fact that accessing the web interface can crash the server adds an additional denial‑of‑service dimension. Because the weakness is a pure authentication bypass (CWE‑306), the primary mitigation is to ensure the authentication checks are enforced or to remove external access to the web interface.
OpenCVE Enrichment