External risk intelligence

Tinycontrol LAN Controller Authentication Bypass Allows Password Change

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2023-54327

The Tinycontrol LAN Controller is a network-connected hardware device typically managed via a web interface. Its primary function as a controller often requires it to be reachable over a network, and such management interfaces are frequently exposed to the internet or reachable from external networks by design to facilitate remote monitoring and control.

Authentication Bypass

Tinycontrol Lan Controller Firmware

1.58a and earlier

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Tinycontrol LAN Controller firmware that allows unauthorized individuals to bypass authentication and change administrator passwords. This could potentially lead to a loss of control over the device's functions and security settings. The main concern is confirming if this technology is in use and if it is exposed in a way that could be targeted.

  • Unauthorized password changes are possible.
  • Potential loss of device control.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by sending a specially crafted API request to the vulnerable controller over the network. This request targets the `/stm.cgi` endpoint and manipulates an authentication parameter to bypass access controls. By successfully exploiting this, an attacker can gain the ability to change the administrative password, effectively taking control of the device.

  • No authentication required to access.
  • Crafted API request to `/stm.cgi`.
  • Unauthorized administrative password changes.

Live Threat

Current exploitation, exposure, and threat context

An authentication bypass vulnerability in Tinycontrol LAN Controller allows unauthenticated attackers to change admin passwords through a crafted API request to the `/stm.cgi` endpoint. This could lead to unauthorized administrative access when the device is reachable over a network.

  • Administrative control of the device.
  • Unauthenticated network request to an API.
  • Unauthorized administrative password changes.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Tinycontrol LAN Controller's authentication bypass vulnerability likely impacts network infrastructure or operational technology teams responsible for managing industrial control systems and network devices. The immediate first step is to determine the scope of deployment, confirm internet-facing exposure, and identify the accountable system owner before prioritizing remediation efforts.

  • Identify all deployed instances.
  • Verify external reachability and criticality.
  • Plan remediation with the system owner.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Tinycontrol LAN Controller?

The Tinycontrol LAN Controller is a hardware device designed for network-based monitoring and automation of electrical equipment, sensors, and environmental data. It acts as an integrated system for remote site management, allowing users to control relays and inputs. Because it serves as a central hub for connected physical infrastructure, it is often networked to enable remote administrative oversight.

What does CWE-862 mean for CVE-2023-54327?

CWE-862 refers to a 'Missing Authorization' weakness. In the context of CVE-2023-54327, this means the software fails to verify the identity of a user before performing a sensitive action. Specifically, the device allows an unauthenticated user to interact with the system's management functions as if they were a logged-in administrator, bypassing the security gate intended to protect the device's password settings.

How is this vulnerability triggered?

An attacker triggers the vulnerability by sending a specific, maliciously crafted API request to the /stm.cgi endpoint on the device. Because the device lacks proper authorization checks for this request, the attacker can manipulate authentication parameters to change the administrative password. Notably, normal, legitimate usage of the device's standard web interface for routine monitoring does not trigger this flaw.

Do I need to worry if my device is not on the internet?

According to Halo Surface Signal, this vulnerability is particularly relevant to devices reachable from external networks. If your controller is exposed directly to the internet, it is at higher risk because the attack requires only network access. If the device is strictly isolated on an internal network, the risk is lower, though it remains a concern for any internal actor who can reach the device's management interface.

How should I respond to this threat?

Start by identifying all instances of Tinycontrol LAN Controller hardware within your network environment. Once identified, verify their network placement to confirm if they are reachable from the public internet. Coordinate with the system owners to audit these devices, limit access to their management interfaces to trusted networks only, and prepare for official updates to address the underlying authentication flaw.

References