CVE-2025-13294
9.3TBEA · TLogger (Communication Box 3rd Generation)
An unauthenticated SQL injection vulnerability in TBEA TLogger V2.1.0.0B0.0.0.0 allows remote attackers to read, modify, or delete data in the device database via unsanitized HTTP parameters.
Executive summary
TBEA TLogger devices are susceptible to a critical SQL injection vulnerability allowing unauthenticated remote attackers to manipulate device databases.
Vulnerability
The web server component of the TBEA TLogger fails to properly validate or parameterize input for multiple HTTP endpoints. This allows an unauthenticated remote attacker to inject malicious SQL commands into the device's CCU.db database.
Business impact
Exploitation of this vulnerability allows for the full compromise of data stored on the TBEA Communication Box. Given the critical 9.3 CVSS score, attackers could modify device settings or delete critical operational data, leading to significant system downtime and potential loss of control over industrial communication infrastructure.
Remediation
Immediate Action: Contact TBEA support or consult the official vendor portal to obtain the latest firmware update for the TBEA Communication Box 3rd Generation.
Proactive Monitoring: Review device access logs for suspicious HTTP requests that contain SQL syntax, such as UNION, SELECT, or DROP commands.
Compensating Controls: Restrict network access to the TBEA TLogger web interface by placing it behind a secure VPN or an isolated management network accessible only to authorized personnel.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
Due to the critical nature of this SQL injection vulnerability, immediate action is required to isolate affected devices from public networks. Organizations should work with TBEA to identify and apply the necessary firmware patches to remediate the vulnerability and secure the device interface.