← Vulnerability feed

Vulnerability record · CVE-2020-13166 · published 19 May 2020

CVE-2020-13166: MyLittleAdmin hardcoded machineKey enables pre-auth RCE

Mylittletools · Mylittleadmin

MyLittleAdmin 3.8 ships a hardcoded machineKey in web.config that is identical across all customer installations. Because that key is used to sign and validate ASP.NET ViewState, a remote attacker can craft serialized ASP code that the management tool deserializes and executes. The flaw is pre-authentication and trivially reachable over the network, making it a serious exposure for any internet-facing instance.

9.8 CVSS 3.1 Critical EPSS 78% · top 0.4% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score, v2 7.5
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with public exploit code and very high EPSS probability warrants immediate remediation.

What it is

MyLittleAdmin 3.8 ships a hardcoded machineKey in web.config that is identical across all customer installations. Because that key is used to sign and validate ASP.NET ViewState, a remote attacker can craft serialized ASP code that the management tool deserializes and executes. The flaw is pre-authentication and trivially reachable over the network, making it a serious exposure for any internet-facing instance.

Impact

An unauthenticated attacker gains remote code execution in the context of the web application, allowing full compromise of the host and any data reachable from it.

Attack surface

Reached over the network via the management tool's ASP.NET endpoint; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the advisory title 'preauth RCE' indicate no authentication or user interaction is required.

Exploitation

Public exploit code is referenced by the Packet Storm and SSD advisories, and EPSS is 0.776 (99.5th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.

What to do

  • Upgrade or patch MyLittleAdmin to a version that does not use a shared hardcoded machineKey; treat 3.8 as unsupported if no fix exists.
  • Replace the hardcoded machineKey in web.config with a unique, randomly generated per-installation key.
  • Remove MyLittleAdmin from internet-facing exposure; restrict access to trusted management networks or VPN only.
  • Enable ViewState MAC validation and disable unsafe deserialization where the platform allows it.
  • Rotate any secrets or credentials that may have been exposed if compromise is suspected.

Detection

  • Monitor web logs for POST requests to MyLittleAdmin endpoints with unusually large or malformed __VIEWSTATE parameters.
  • Alert on ASP.NET worker process spawning child processes such as cmd.exe, powershell.exe or w3wp.exe anomalies.
  • Hunt for outbound connections from the web server to unknown hosts following MyLittleAdmin requests.
  • Audit web.config files across deployments for the known hardcoded machineKey value.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13166 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

4.3CVE-2012-4015Mylittletools mylittleadmin cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the management screen in myLittleTools myLittleAdmin for SQL Server 2000 allows remote attackers to injec…EPSS 0.93%10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed6.5CVE-2019-6693FortiOS hard-coded key exposes backup file secretsFortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data i…KEVEPSS 5.8%analysed9.8CVE-2025-30406Gladinet CentreStack hardcoded machineKey deserialization RCEGladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) uses a hardcoded machineKey in the portal's web.config, allowing deserializ…KEVEPSS 94%analysed9.8CVE-2024-20439Cisco Smart Licensing Utility hard-coded admin credential allows remote loginCisco Smart Licensing Utility (CSLU) contains an undocumented static credential for an administrative account. An unauthenticated remote attacker who…KEVEPSS 97%analysed8.1CVE-2021-44207Acclaim USAHERDS hard-coded credentials allow remote compromiseAcclaim USAHERDS through 7.4.0.1 ships with hard-coded credentials (CWE-798). Anyone who knows or extracts those credentials can authenticate to the …KEVEPSS 18%analysed9.1CVE-2024-28987SolarWinds Web Help Desk hardcoded credential flawSolarWinds Web Help Desk contains a hardcoded credential vulnerability (CWE-798) that lets a remote, unauthenticated attacker reach internal function…KEVEPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2020-13166), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.