PT-2025-54254 · Unknown · Tinycontrol Lan Controller
Published
2025-12-30
·
Updated
2025-12-31
·
CVE-2023-54327
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tinycontrol LAN Controller version 1.58a
Description
An authentication bypass allows unauthenticated attackers to change admin passwords. This is achieved by sending a crafted API request to the
/stm.cgi endpoint with a specially crafted authentication parameter, disabling access controls and allowing modification of administrative credentials. The vulnerable parameter is the authentication parameter within the API request.Recommendations
Apply any available updates to address the authentication bypass. As a temporary workaround, restrict access to the
/stm.cgi endpoint.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tinycontrol Lan Controller