Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-54327 1 Tinycontrol 2 Lan Controller, Lan Controller Firmware 2026-01-13 7.5 High
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.