VYPR
Unrated severityNVD Advisory· Published Dec 30, 2025· Updated Mar 5, 2026

Tinycontrol LAN Controller 1.58a Authentication Bypass via Admin Password Change

CVE-2023-54327

Description

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.