ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2023-54327”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2023-54327
Published
2025-12-30
CVSS:
9.3
ShadowTrackr CVSS:
8.1
Summary:
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.