---
id: CVE-2025-13294
title: >-
  An unauthenticated SQL injection vulnerability exists in the web server of
  TBEA TLogger V2.1.0.0B0.0.0.0
summary: >-
  An unauthenticated SQL injection vulnerability exists in the web server of
  TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate
  attacker-controlled parameters directly into SQLite queries without sufficient
  validation or pa…
severity: none
cwe:
  - CWE-89
published: '2026-08-10'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T11:10:00.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13294'
references:
  - url: 'https://en.tbea.com/about.html'
    label: office@cyberdanube.com
tags:
  - nvd
ingestedAt: '2026-09-29T11:32:41.222Z'
---

## Overview

An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated attacker can exploit these endpoints to read, modify, or delete data stored in the device's CCU.db database.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
