Description
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.
Problem types
Product status
Unknown (semver)
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/51732 (ExploitDB-51732)
www.tinycontrol.pl (Tinycontrol Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5787.php (Zero Science Lab Disclosure (ZSL-2023-5787))
www.vulncheck.com/...cation-bypass-via-admin-password-change (VulnCheck Advisory: Tinycontrol LAN Controller 1.58a Authentication Bypass via Admin Password Change)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.