Описание
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.
Ссылки
- ExploitThird Party Advisory
- Product
- Third Party Advisory
- Third Party AdvisoryExploit
- Third Party AdvisoryExploit
Уязвимые конфигурации
Одновременно
EPSS
7.5 High
CVSS3
9.8 Critical
CVSS3
Дефекты
Связанные уязвимости
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.
EPSS
7.5 High
CVSS3
9.8 Critical
CVSS3