Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and configuration loss.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tinycontrol
Tinycontrol lan Controller |
|
| Vendors & Products |
Tinycontrol
Tinycontrol lan Controller |
Wed, 12 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and configuration loss. | |
| Title | Tinycontrol LAN Controller v3 (LK3) Remote DoS | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-11-12T22:06:26.619Z
Updated: 2025-11-13T17:00:32.000Z
Reserved: 2025-11-12T21:06:12.202Z
Link: CVE-2023-7329
Updated: 2025-11-13T17:00:24.411Z
Status : Received
Published: 2025-11-12T22:15:42.830
Modified: 2025-11-12T22:15:42.830
Link: CVE-2023-7329
No data.
ReportizFlow