NONE · 0

CVE-2023-7329

Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send cr...

Vulnerability Description

Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and configuration loss.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-7329?

CVE-2023-7329 is a documented vulnerability. Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send cr...

How severe is CVE-2023-7329?

CVSS scoring is not yet available for CVE-2023-7329. Check NVD for updates.

Is there a patch for CVE-2023-7329?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.