CVE-2023-54327
CRITICALTinycontrol LAN Controller < 1.58a - Unauthenticated Authentication Bypass via /stm.cgi Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-54327. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit leverages an insecure access control vulnerability in Tinycontrol LAN Controller v3 (LK3) 1.58a, allowing an unauthenticated attacker to change the admin password via a crafted HTTP request. The script uses base64 encoding to bypass authentication and modify the password.
Description
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.
Exploits (1)
This exploit leverages an insecure access control vulnerability in Tinycontrol LAN Controller v3 (LK3) 1.58a, allowing an unauthenticated attacker to change the admin password via a crafted HTTP request. The script uses base64 encoding to bypass authentication and modify the password.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H