vendor:
Tinycontrol LAN Controller v3 (LK3)
by:
LiquidWorm
6.1
CVSS
HIGH
Credentials Extraction
CWE
Product Name: Tinycontrol LAN Controller v3 (LK3)
Affected Version From: <=1.58a, HW 3.8
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: lwIP
2023
Tinycontrol LAN Controller v3 (LK3) – Remote Credentials Extraction
An unauthenticated attacker can retrieve the controller's configuration backup file and extract sensitive information that can allow him/her/them to bypass security controls and penetrate the system in its entirety.
Mitigation:
Implement proper access controls and authentication mechanisms to prevent unauthorized access to the controller's configuration backup file.