What is CVE-2025-15681?
TBEA TLogger V2.1.0.0B0.0.0.0 has an authentication bypass vulnerability in its web server. After a user has previously authenticated, an unauthenticated attacker can access protected functionality via the /index.asp endpoint without valid credentials. It is recommended to isolate the device and request a patch from the vendor.
Azərbaycanca: TBEA TLogger V2.1.0.0B0.0.0.0 cihazının veb serverində autentifikasiyadan yan keçmə zəifliyi aşkar edilib. Əvvəlcədən autentifikasiya olunmuş istifadəçidən sonra, /index.asp endpoint-i vasitəsilə etimadnamə tələb olunmadan qorunan funksionallığa icazəsiz giriş mümkündür. Cihazı şəbəkədən təcrid etmək və istehsalçıdan yamaq tələb etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
In which device was CVE-2025-15681 discovered?
The vulnerability was discovered in version V2.1.0.0B0.0.0.0 of the TBEA TLogger device.
What is the recommended mitigation for CVE-2025-15681?
It is recommended to isolate the device from the network and request a patch from the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.