| CVE ID | CVE-2025-11500 |
| Publication date | 16 March 2026 |
| Vendor | tinycontrol |
| Product | tcPDU and LAN Controllers: LK3.5, LK3.9 and LK4 |
| Vulnerable versions | Before 1.36 for tcPDU Before 1.67 for LK3.5 - hardware versions: 3.5, 3.6, 3.7 and 3.8 Before 1.75 for LK3.9 - hardware version 3.9 Before 1.38 for LK4 - hardware version 4.0 |
| Vulnerability type (CWE) | Weak Encoding for Password (CWE-261) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2025-15587 |
| Publication date | 16 March 2026 |
| Vendor | tinycontrol |
| Product | tcPDU and LAN Controllers: LK3.5, LK3.9 and LK4 |
| Vulnerable versions | Before 1.36 for tcPDU Before 1.67 for LK3.5 - hardware versions: 3.5, 3.6, 3.7 and 3.8 Before 1.75 for LK3.9 - hardware version 3.9 Before 1.38 for LK4 - hardware version 4.0 |
| Vulnerability type (CWE) | Direct Request ('Forced Browsing') (CWE-425) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerabilities in tinycontrol devices (tcPDU and LAN Controllers: LK3.5, LK3.9 and LK4) and participated in coordination of their disclosure.
The vulnerability CVE-2025-11500: Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off (which is a default setting), an unauthenticated attacker on the local network can obtain usernames and encoded passwords for interface management portal by inspecting the HTTP response of the server when visiting the login page, which contains a JSON file with these details. Both normal and admin users credentials are exposed.
The vulnerability CVE-2025-15587: Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an administrator's password by directly accessing a specific resource inaccessible via a graphical interface.
These vulnerabilities have been fixed in firmware versions:
- 1.36 for tcPDU
- 1.67 for LK3.5 - hardware versions: 3.5, 3.6, 3.7 and 3.8
- 1.75 for LK3.9 - hardware version 3.9
- 1.38 1.38 for LK4 - hardware version 4.0.
Credits
We thank Paweł Różański from Securitum for reporting CVE-2025-11500 and the tinycontrol company for reporting CVE-2025-15587.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.