Back to overview

CVE-2023-53739

CRITICAL Exploitation: PoC
9.9
CVSS 4.0
Description
Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication.

Metadata

CVE ID
CVE-2023-53739
State
PUBLISHED
Assigner
VulnCheck
Reserved
2025-12-07 13:16 UTC
Published
2025-12-09 20:49 UTC
Last updated
2026-07-28 01:47 UTC
Primary CWE
CWE-260
CWE-260: Password in Configuration File
Vendor / Product
Tinycontrol / Tinycontrol LAN Controller v
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
Tinycontrol LK <=1.58a, HW 3.8
Tinycontrol Tinycontrol LAN Controller v <=1.58a, HW 3.8
Weakness (CWE)
CWESourceDescription
CWE-260 cna CWE-260: Password in Configuration File
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
References (4)
Back to overview