CRITICAL 9.3 NVD
CVE-2025-13294
An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlle
An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated attacker can exploit these endpoints to read, modify, or delete data stored in the device's CCU.db database.
References
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-10 via NVD.
Risk Timeline
CVE Disclosed2026-08-10 · -1 days ago
Remediation Resources
Analysis & PoC
en.tbea.com/about.html
vulnfeed aggregates 7833 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.