Vulnerability Description
Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication.
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/51731
- https://www.tinycontrol.pl
- https://www.vulncheck.com/advisories/tinycontrol-lan-controller-v3-lk3-unauthent
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5786.php
FAQ
What is CVE-2023-53739?
CVE-2023-53739 is a documented vulnerability. Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attacker...
How severe is CVE-2023-53739?
CVSS scoring is not yet available for CVE-2023-53739. Check NVD for updates.
Is there a patch for CVE-2023-53739?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.