# Tinycontrol PDU firmware exposes admin passwords

Published: 2026-03-16 · Severity: medium · Sectors: infrastructure, manufacturing
Canonical: https://vorant.io/reports/430b0d3b-8359-5773-8249-dd3b90d614ad/tinycontrol-pdu-firmware-exposes-admin-passwords

> Two vulnerabilities in tinycontrol tcPDU and LAN Controller devices let local network attackers or low-privileged users obtain admin credentials.

CERT Polska coordinated disclosure of two vulnerabilities affecting tinycontrol power distribution units (tcPDU) and LAN Controllers (LK3.5, LK3.9, LK4). CVE-2025-11500 stems from a default configuration where a secondary authentication mechanism protecting server resources is disabled, allowing an unauthenticated attacker on the local network to retrieve a JSON file containing usernames and encoded passwords for both normal and admin accounts simply by loading the login page. CVE-2025-15587 allows a low-privileged authenticated user to directly access a hidden resource not exposed via the web GUI to read the administrator's password.

Both issues affect devices commonly used for remote power management of networked equipment, meaning successful exploitation could grant an attacker administrative control over power distribution infrastructure. The vendor has released fixed firmware versions (1.36 for tcPDU, 1.67 for LK3.5, 1.75 for LK3.9, and 1.38 for LK4) addressing both flaws. There is no indication of active exploitation; this is a coordinated disclosure with vendor patches already available.

## Mentioned in this report

- Vulnerabilities: CVE-2025-11500, CVE-2025-15587

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2025-11500

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/430b0d3b-8359-5773-8249-dd3b90d614ad/tinycontrol-pdu-firmware-exposes-admin-passwords.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
