CVE-2025-15682
8.7TBEA · TBEA TLogger (TBEA Communication Box 3rd Generation)
TBEA TLogger is susceptible to resource exhaustion due to improper allocation limits, allowing unauthenticated attackers to cause a denial of service.
Executive summary
A vulnerability in the TBEA TLogger communication box allows unauthenticated attackers to trigger a denial of service condition through resource exhaustion.
Vulnerability
This vulnerability is caused by a failure to implement resource limits or throttling (CWE-770). An unauthenticated remote attacker can exploit this to consume excessive system resources, leading to a complete service outage.
Business impact
The inability to properly manage resource allocation poses a severe threat to operational continuity, as the device can be rendered unresponsive by an attacker. Given the CVSS score of 8.7, this is a high-severity issue that could lead to significant downtime for critical industrial communication infrastructure.
Remediation
Immediate Action: Contact the vendor for firmware update availability, as no specific patch version is currently identified.
Proactive Monitoring: Monitor system resource utilization and network traffic logs for spikes in requests that may indicate an attempt to overwhelm the device.
Compensating Controls: Implement network-level access control lists to restrict traffic to the TLogger device to trusted management IPs only.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of communication infrastructure, administrators should prioritize restricting network access to the affected TBEA devices. Monitor vendor channels closely for the release of a security update and apply it immediately upon availability.