{"id":"CVE-2025-15682","title":"TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server","summary":"TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/ endpoint, causing the web server to create persistent fi…","severity":"none","cwe":["CWE-770"],"published":"2026-08-10","updated":"2026-09-29","sourceUpdated":"2026-09-29T11:10:00.150","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15682","references":[{"url":"https://en.tbea.com/about.html","label":"office@cyberdanube.com"}],"tags":["nvd"],"ingestedAt":"2026-09-29T11:32:41.224Z","slug":"CVE-2025-15682","body":"## Overview\n\nTBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/ endpoint, causing the web server to create persistent files containing attacker-controlled data under /opt/myapp/webserver/. The generated files are not removed because the web server attempts to move them into a non-existent directory. Repeated requests can therefore exhaust available storage and cause a denial-of-service condition.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}