Tinycontrol PDU firmware exposes admin passwords
Two vulnerabilities in tinycontrol tcPDU and LAN Controller devices let local network attackers or low-privileged users obtain admin credentials.
CERT Polska coordinated disclosure of two vulnerabilities affecting tinycontrol power distribution units (tcPDU) and LAN Controllers (LK3.5, LK3.9, LK4). CVE-2025-11500 stems from a default configuration where a secondary authentication mechanism protecting server resources is disabled, allowing an unauthenticated attacker on the local network to retrieve a JSON file containing usernames and encoded passwords for both normal and admin accounts simply by loading the login page. CVE-2025-15587 allows a low-privileged authenticated user to directly access a hidden resource not exposed via the web GUI to read the administrator's password.
Both issues affect devices commonly used for remote power management of networked equipment, meaning successful exploitation could grant an attacker administrative control over power distribution infrastructure. The vendor has released fixed firmware versions (1.36 for tcPDU, 1.67 for LK3.5, 1.75 for LK3.9, and 1.38 for LK4) addressing both flaws. There is no indication of active exploitation; this is a coordinated disclosure with vendor patches already available.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-11500
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free