What is CVE-2025-15682?
This is an unauthenticated resource exhaustion vulnerability in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. A remote attacker can send crafted PUT requests to the /tmp/ endpoint, causing the server to persistently create files under /opt/myapp/webser with attacker-controlled data, potentially filling the disk and causing denial of service. Isolate the device at the network level and await a patch from the vendor.
Azərbaycanca: Bu, TBEA TLogger V2.1.0.0B0.0.0.0 cihazının veb serverində autentifikasiya tələb etməyən resurs tükənməsi (resource exhaustion) zəifliyidir. Uzaqdan bir hücumçu /tmp/ endpointinə xüsusi PUT sorğuları göndərərək /opt/myapp/webser qovluğu altında davamlı fayllar yarada bilər ki, bu da disk sahəsini dolduraraq xidmət pozuntusuna səbəb ola bilər. Cihazı şəbəkə səviyyəsində təcrid etmək və istehsalçıdan yamaq gözləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: TBEA
FAQ2
Which device is affected by CVE-2025-15682?
This vulnerability affects the web server of TBEA TLogger V2.1.0.0B0.0.0.0.
What can an attacker achieve by exploiting CVE-2025-15682?
An attacker can send crafted PUT requests to the /tmp/ endpoint, potentially filling the disk and causing denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.