Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcw3-qjrp-gq57

Опубликовано: 31 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 7.5

Описание

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.

EPSS

Процентиль: 78%
0.01188
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.

EPSS

Процентиль: 78%
0.01188
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-862