TBEA TLogger是TBEA公司的一系列专用于光伏系统监控和管理平台的设备。 TBEA TLogger V2.1.0.0B0.0.0.0及之前版本存在信任管理问题漏洞,该漏洞源于硬编码或默认的root账户凭据,root密码可从/etc/shadow中的密码哈希恢复,可能导致未经身份验证的远程攻击者通过暴露的SSH服务获取root级访问权限,并完全控制设备。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | ≤ V2.1.0.0B0.0.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | 0 ~ V2.1.0.0B0.0.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-13294 | 9.3 CRITICAL | Unauthenticated SQL Injection |
| CVE-2025-15681 | 9.2 CRITICAL | Insufficient Webserver Authentication |
| CVE-2025-15683 | 8.8 HIGH | Multiple Unauthenticated Denial-of-Service Conditions |
| CVE-2025-15682 | 8.7 HIGH | Unauthenticated Resource Exhaustion |
| CVE-2025-15680 | 2.4 LOW | Information Disclosure via UART |
No comments yet