VORANT. Threat Intelligence Sign in Get the full feed

Tinycontrol PDU firmware exposes admin passwords

medium vulnerability infrastructuremanufacturing

Two vulnerabilities in tinycontrol tcPDU and LAN Controller devices let local network attackers or low-privileged users obtain admin credentials.

CERT Polska coordinated disclosure of two vulnerabilities affecting tinycontrol power distribution units (tcPDU) and LAN Controllers (LK3.5, LK3.9, LK4). CVE-2025-11500 stems from a default configuration where a secondary authentication mechanism protecting server resources is disabled, allowing an unauthenticated attacker on the local network to retrieve a JSON file containing usernames and encoded passwords for both normal and admin accounts simply by loading the login page. CVE-2025-15587 allows a low-privileged authenticated user to directly access a hidden resource not exposed via the web GUI to read the administrator's password.

Both issues affect devices commonly used for remote power management of networked equipment, meaning successful exploitation could grant an attacker administrative control over power distribution infrastructure. The vendor has released fixed firmware versions (1.36 for tcPDU, 1.67 for LK3.5, 1.75 for LK3.9, and 1.38 for LK4) addressing both flaws. There is no indication of active exploitation; this is a coordinated disclosure with vendor patches already available.

Mentioned in this report

Vulnerabilities CVE-2025-11500CVE-2025-15587

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-11500

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free