Executive brief
Tinycontrol LAN controllers and power distribution units (tcPDU) contain a security flaw where user and administrator credentials can be exposed to unauthorized individuals on the same local network. By default, the devices do not properly protect the login page, allowing an attacker to view usernames and encoded passwords by simply inspecting the data sent by the device's web server. This could lead to full unauthorized control of the device, potentially allowing attackers to disrupt power management or manipulate connected industrial equipment.
Technical details
The vulnerability (CWE-201, CWE-261) exists in the web management interface of Tinycontrol tcPDU and LAN Controllers. These devices utilize two authentication mechanisms: one for general server resources and one specifically for interface management. When the resource protection mechanism is disabled (the default configuration), the server includes a JSON file containing usernames and encoded passwords for all users, including administrators, in the HTTP response when a user visits the login page. An unauthenticated attacker on the local network can capture this response to extract credentials. The issue has been addressed by integrating the web interface with Basic Authentication by default in the latest firmware updates.
Affected products
- Tinycontrol tcPDU Before 1.36
- Tinycontrol LAN Controller LK3.5 (HW 3.5, 3.6, 3.7, 3.8) Before 1.67
- Tinycontrol LAN Controller LK3.9 (HW 3.9) Before 1.75
- Tinycontrol LAN Controller LK4 (HW 4.0) Before 1.38
Timeline
- 2026-03-16: disclosed
- 2026-03-16: advisory
- 2026-01-13: patched: Firmware fixes released for LK3.5, LK3.9, LK4, and tcPDU.