Information Disclosure via UART
Summary
| CVE | CVE-2025-15680 |
|---|---|
| State | PUBLISHED |
| Assigner | CyberDanube |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 20:17:25 UTC |
| Updated | 2026-08-12 19:17:28 UTC |
| Description | TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device. |
Risk And Classification
Primary CVSS: v4.0 2.4 LOW from [email protected]
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.001540000 probability, percentile 0.051120000 (date 2026-08-13)
Problem Types: CWE-497 | CWE-497 CWE-497
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 2.4 | LOW | CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 2.4 | LOW | CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
PhysicalAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
LowIntegrity
NoneAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TBEA | TBEA TLogger TBEA Communication Box 3rd Generation | affected V2.1.0.0B0.0.0.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| en.tbea.com/about.html | [email protected] | en.tbea.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: S. Eisenreich-Dietz (CyberDanube) (en)
CNA: T. Weber (CyberDanube) (en)
CNA: F. Koroknai (en)
CNA: D. Blagojevic (en)
There are currently no legacy QID mappings associated with this CVE.