Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and configuration loss.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco wireless Lan Controller Software Firmware |
|
| CPEs | cpe:2.3:o:cisco:wireless_lan_controller_software_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cisco
Cisco wireless Lan Controller Software Firmware |
Thu, 13 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tinycontrol
Tinycontrol lan Controller |
|
| Vendors & Products |
Tinycontrol
Tinycontrol lan Controller |
Wed, 12 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and configuration loss. | |
| Title | Tinycontrol LAN Controller v3 (LK3) Remote DoS | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-11-12T22:06:26.619Z
Updated: 2026-03-05T12:03:27.518Z
Reserved: 2025-11-12T21:06:12.202Z
Link: CVE-2023-7329
Updated: 2025-11-13T17:00:24.411Z
Status : Awaiting Analysis
Published: 2025-11-12T22:15:42.830
Modified: 2025-11-14T16:42:30.503
Link: CVE-2023-7329
No data.