TBEA TLogger是TBEA公司的一系列专用于光伏系统监控和管理平台的设备。 TBEA TLogger V2.1.0.0B0.0.0.0及之前版本存在信息泄露漏洞,该漏洞源于设备电路板上的UART接口未充分保护,物理邻近的攻击者可连接该接口观察设备启动过程和运行时调试输出,泄露操作系统信息、软件版本、网络配置、文件系统路径等实现和调试信息,可能帮助攻击者进一步入侵设备。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | ≤ V2.1.0.0B0.0.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | 0 ~ V2.1.0.0B0.0.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-13294 | 9.3 CRITICAL | Unauthenticated SQL Injection |
| CVE-2025-13293 | 9.3 CRITICAL | Backdoor / default root credentials |
| CVE-2025-15681 | 9.2 CRITICAL | Insufficient Webserver Authentication |
| CVE-2025-15683 | 8.8 HIGH | Multiple Unauthenticated Denial-of-Service Conditions |
| CVE-2025-15682 | 8.7 HIGH | Unauthenticated Resource Exhaustion |
No comments yet