CVE-2023-54327

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tinycontrol:lan_controller_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tinycontrol:lan_controller:3.8:*:*:*:*:*:*:*

History

16 Jan 2026, 19:16

Type Values Removed Values Added
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5787.php - Third Party Advisory, Exploit () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5787.php - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.8

13 Jan 2026, 21:42

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/51732 - () https://www.exploit-db.com/exploits/51732 - Exploit, Third Party Advisory
References () https://www.tinycontrol.pl - () https://www.tinycontrol.pl - Product
References () https://www.vulncheck.com/advisories/tinycontrol-lan-controller-a-authentication-bypass-via-admin-password-change - () https://www.vulncheck.com/advisories/tinycontrol-lan-controller-a-authentication-bypass-via-admin-password-change - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5787.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5787.php - Third Party Advisory, Exploit
CPE cpe:2.3:o:tinycontrol:lan_controller_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tinycontrol:lan_controller:3.8:*:*:*:*:*:*:*
First Time Tinycontrol lan Controller Firmware
Tinycontrol
Tinycontrol lan Controller

02 Jan 2026, 15:15

Type Values Removed Values Added
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5787.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5787.php -

30 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-30 23:15

Updated : 2026-01-16 19:16


NVD link : CVE-2023-54327

Mitre link : CVE-2023-54327

CVE.ORG link : CVE-2023-54327


JSON object : View

Products Affected

tinycontrol

  • lan_controller
  • lan_controller_firmware
CWE
CWE-862

Missing Authorization