A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://en.tbea.com/about.html |
|
History
Mon, 10 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device. | |
| Title | Backdoor / default root credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CyberDanube
Published:
Updated: 2026-08-10T19:24:10.104Z
Reserved: 2025-11-17T11:17:17.483Z
Link: CVE-2025-13293
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T20:45:05Z