Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in Tinycontrol LAN Controller firmware that allows unauthorized individuals to bypass authentication and change administrator passwords. This could potentially lead to a loss of control over the device's functions and security settings. The main concern is confirming if this technology is in use and if it is exposed in a way that could be targeted.
- Unauthorized password changes are possible.
- Potential loss of device control.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
Attackers can exploit this vulnerability by sending a specially crafted API request to the vulnerable controller over the network. This request targets the `/stm.cgi` endpoint and manipulates an authentication parameter to bypass access controls. By successfully exploiting this, an attacker can gain the ability to change the administrative password, effectively taking control of the device.
- No authentication required to access.
- Crafted API request to `/stm.cgi`.
- Unauthorized administrative password changes.
Live Threat
Current exploitation, exposure, and threat context
An authentication bypass vulnerability in Tinycontrol LAN Controller allows unauthenticated attackers to change admin passwords through a crafted API request to the `/stm.cgi` endpoint. This could lead to unauthorized administrative access when the device is reachable over a network.
- Administrative control of the device.
- Unauthenticated network request to an API.
- Unauthorized administrative password changes.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Tinycontrol LAN Controller's authentication bypass vulnerability likely impacts network infrastructure or operational technology teams responsible for managing industrial control systems and network devices. The immediate first step is to determine the scope of deployment, confirm internet-facing exposure, and identify the accountable system owner before prioritizing remediation efforts.
- Identify all deployed instances.
- Verify external reachability and criticality.
- Plan remediation with the system owner.