Unrated severityNVD Advisory· Published Dec 30, 2025· Updated Mar 5, 2026
Tinycontrol LAN Controller 1.58a Authentication Bypass via Admin Password Change
CVE-2023-54327
Description
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.
Affected products
2- Range: = 1.58a
- Tinycontrol/LAN Controllerv5Range: HW 3.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/51732mitreexploit
- www.vulncheck.com/advisories/tinycontrol-lan-controller-a-authentication-bypass-via-admin-password-changemitrethird-party-advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5787.phpmitrethird-party-advisory
- www.tinycontrol.plmitreproduct
News mentions
0No linked articles in our index yet.