HIGH
Tinycontrol LAN Controller v3 (LK3) Remote DoS
Published Nov 12, 2025
8.7
HIGHCVSS 4.0
EPSS 0.91%
Description
Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and configuration loss.
Affected products
-
- Version 0StatusaffectedConstraints<=1.58a
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Tinycontrol | Lan Controller | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://exchange.xforce.ibmcloud.com/vulnerabilities/275810 vdb-entry
- https://packetstormsecurity.com/files/174455/ exploit
- https://tinycontrol.pl/en/archives/lan-controller-35/ product
- https://www.exploit-db.com/exploits/51730 exploit
- https://www.vulncheck.com/advisories/tinycontrol-lan-controller-v3-remote-dos third-party-advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5785.php technical-descriptionexploit
| Link | Providers | Tags |
|---|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/275810 | vdb-entry | |
| https://packetstormsecurity.com/files/174455/ | exploit | |
| https://tinycontrol.pl/en/archives/lan-controller-35/ | product | |
| https://www.exploit-db.com/exploits/51730 | exploit | |
| https://www.vulncheck.com/advisories/tinycontrol-lan-controller-v3-remote-dos | third-party-advisory | |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5785.php | technical-descriptionexploit |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Nov 12, 2025
Updated Apr 7, 2026
Reserved Nov 12, 2025
Link CVE-2023-7329
CISA Vulnrichment
Updated Nov 13, 2025