CVE-2025-13294

An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated attacker can exploit these endpoints to read, modify, or delete data stored in the device's CCU.db database.
CVSS

No CVSS.

References
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 20:17

Updated : 2026-09-03 16:41


NVD link : CVE-2025-13294

Mitre link : CVE-2025-13294

CVE.ORG link : CVE-2025-13294


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')