Vulnerability record · CVE-2020-13166 · published 19 May 2020
CVE-2020-13166: MyLittleAdmin hardcoded machineKey enables pre-auth RCE
Mylittletools · Mylittleadmin
MyLittleAdmin 3.8 ships a hardcoded machineKey in web.config that is identical across all customer installations. Because that key is used to sign and validate ASP.NET ViewState, a remote attacker can craft serialized ASP code that the management tool deserializes and executes. The flaw is pre-authentication and trivially reachable over the network, making it a serious exposure for any internet-facing instance.
Description
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with public exploit code and very high EPSS probability warrants immediate remediation.
What it is
MyLittleAdmin 3.8 ships a hardcoded machineKey in web.config that is identical across all customer installations. Because that key is used to sign and validate ASP.NET ViewState, a remote attacker can craft serialized ASP code that the management tool deserializes and executes. The flaw is pre-authentication and trivially reachable over the network, making it a serious exposure for any internet-facing instance.
Impact
An unauthenticated attacker gains remote code execution in the context of the web application, allowing full compromise of the host and any data reachable from it.
Attack surface
Reached over the network via the management tool's ASP.NET endpoint; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the advisory title 'preauth RCE' indicate no authentication or user interaction is required.
Exploitation
Public exploit code is referenced by the Packet Storm and SSD advisories, and EPSS is 0.776 (99.5th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Upgrade or patch MyLittleAdmin to a version that does not use a shared hardcoded machineKey; treat 3.8 as unsupported if no fix exists.
- Replace the hardcoded machineKey in web.config with a unique, randomly generated per-installation key.
- Remove MyLittleAdmin from internet-facing exposure; restrict access to trusted management networks or VPN only.
- Enable ViewState MAC validation and disable unsafe deserialization where the platform allows it.
- Rotate any secrets or credentials that may have been exposed if compromise is suspected.
Detection
- Monitor web logs for POST requests to MyLittleAdmin endpoints with unusually large or malformed __VIEWSTATE parameters.
- Alert on ASP.NET worker process spawning child processes such as cmd.exe, powershell.exe or w3wp.exe anomalies.
- Hunt for outbound connections from the web server to unknown hosts following MyLittleAdmin requests.
- Audit web.config files across deployments for the known hardcoded machineKey value.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157808/Plesk-myLittleAdmin-ViewState-.NET-Deserialization.html | ExploitThird Party AdvisoryVDB Entry |
| https://ssd-disclosure.com/ssd-advisory-mylittleadmin-preauth-rce/ | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/157808/Plesk-myLittleAdmin-ViewState-.NET-Deserialization.html | ExploitThird Party AdvisoryVDB Entry |
| https://ssd-disclosure.com/ssd-advisory-mylittleadmin-preauth-rce/ | ExploitThird Party Advisory |
Track CVE-2020-13166 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13166), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.