Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Tinycontrol LAN Controller Unauthenticated Configuration Backup Vulnerability Allowing Credential Extraction

Vulnerability

A vulnerability exists in Tinycontrol LAN Controller v3 LK3, specifically in version 1.58a, that allows remote attackers to download configuration backup files containing sensitive credentials. The vulnerability is unauthenticated, enabling attackers to retrieve the 'lk3_settings.bin' file and extract base64-encoded user and admin passwords without any authentication.

Impact

Exploitation of this vulnerability leads to unauthorized access to user and admin credentials, which can be used to bypass security controls and gain full access to the system.

Reproduction

To reproduce this vulnerability, send a request to the device for the 'lk3_settings.bin' file. If the request is successful and the file is returned, it can be saved locally. Once the file is obtained, extract the base64-encoded passwords for the user and admin by searching for specific patterns in the file's content. Decode the extracted base64 strings to retrieve the plaintext passwords.

Added: Dec 9, 2025, 9:46 PM
Updated: Dec 9, 2025, 9:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
9.1
remediation
0.0
relevance
1.3
threat
8.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.