Security Advisory

CVE-2025-13293

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-10 19:24:10
Last updated 2026-08-12 18:06:27
Assigner CyberDanube
CVSS score 9.3
State PUBLISHED

Description

A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device.