Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Tinycontrol
Tinycontrol lan Controller
Vendors & Products Tinycontrol
Tinycontrol lan Controller

Wed, 10 Dec 2025 16:30:00 +0000


Wed, 10 Dec 2025 16:00:00 +0000


Tue, 09 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication.
Title Tinycontrol LAN Controller v3 LK3 1.58a Unauthenticated Configuration Backup Disclosure
Weaknesses CWE-260
References
Metrics cvssV4_0

{'score': 9.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-10T15:43:19.808Z

Reserved: 2025-12-07T13:16:38.431Z

Link: CVE-2023-53739

cve-icon Vulnrichment

Updated: 2025-12-09T21:05:49.123Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-09T21:15:51.897

Modified: 2025-12-12T15:19:07.567

Link: CVE-2023-53739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-10T17:48:55Z

Weaknesses