CVE-2023-54327

CRITICAL

Tinycontrol LAN Controller < 1.58a - Unauthenticated Authentication Bypass via /stm.cgi Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-54327. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit leverages an insecure access control vulnerability in Tinycontrol LAN Controller v3 (LK3) 1.58a, allowing an unauthenticated attacker to change the admin password via a crafted HTTP request. The script uses base64 encoding to bypass authentication and modify the password.

Description

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textremotehardware
https://www.exploit-db.com/exploits/51732

This exploit leverages an insecure access control vulnerability in Tinycontrol LAN Controller v3 (LK3) 1.58a, allowing an unauthenticated attacker to change the admin password via a crafted HTTP request. The script uses base64 encoding to bypass authentication and modify the password.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Tinycontrol LAN Controller v3 (LK3) <=1.58a
No auth needed
Prerequisites: Network access to the target device · Knowledge of the target IP address
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Product product
https://www.tinycontrol.pl
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/51732
Exploit, Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5787.php

Scores

CVSS v3 9.8
EPSS 0.0194
EPSS Percentile 83.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Products (3)
Tinycontrol/LAN Controller < 1.58a
Tinycontrol/LAN Controller HW 3.8
tinycontrol/lan_controller_firmware < 1.58a
Published Dec 30, 2025
Tracked Since Feb 18, 2026