Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tinycontrol
Tinycontrol lan Controller |
|
| Vendors & Products |
Tinycontrol
Tinycontrol lan Controller |
Wed, 10 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 10 Dec 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication. | |
| Title | Tinycontrol LAN Controller v3 LK3 1.58a Unauthenticated Configuration Backup Disclosure | |
| Weaknesses | CWE-260 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:06:46.394Z
Reserved: 2025-12-07T13:16:38.431Z
Link: CVE-2023-53739
Updated: 2025-12-09T21:05:49.123Z
Status : Deferred
Published: 2025-12-09T21:15:51.897
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-53739
No data.
OpenCVE Enrichment
Updated: 2025-12-10T17:48:55Z