Impact
A remote attacker who can reach the web server can trigger a device reboot, reset, data erasure, or a segmentation fault by sending crafted HTTP requests to the affected endpoints. The firmware version 2.1.0.0B0.0.0.0 uses unsafe string functions such as sprintf() and strcat() without bounds checking, allowing malicious input to overflow buffers and crash the web server. The result is a loss of service and potential data loss, as reflected by the CVSS score of 8.8.
Affected Systems
The vulnerability is present in TBEA TLogger version 2.1.0.0B0.0.0.0, released for the TBEA Communication Box 3rd Generation. The listed endpoints that can be abused include onRestart, onReset, ClearData, uploadInvFile, getIndiaRPData, YearCaparity, TotalfaultData, recordData, InvHistoryData, CollectHistoryData, InvFaultData, GetPortTableByParm, and UpdatePortConfig.
Risk and Exploitability
The flaw is exploitable remotely and does not require authentication, which makes it highly accessible to attackers. Because the vulnerability is triggered by specific HTTP calls, an attacker can automate the process to bring the device down. The EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalog, but the high CVSS score underscores the severity and potential impact of a successful exploit.
OpenCVE Enrichment