vendor:
LAN Controller v3
by:
LiquidWorm
6.1
CVSS
HIGH
Insecure Access Control
284
CWE
Product Name: LAN Controller v3
Affected Version From: <=1.58a
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:tinycontrol:lan_controller_v3
Platforms Tested: lwIP
2023
Tinycontrol LAN Controller v3 (LK3) 1.58a – Remote Admin Password Change
The application suffers from an insecure access control allowing an unauthenticated attacker to change accounts passwords and bypass authentication gaining panel control access.
Mitigation:
Implement proper access control mechanisms, such as strong authentication and authorization checks.