Junglewise Threat Intelligence

CVE-2025-15587: Tinycontrol LAN Controllers and tcPDU admin password disclosure via forced browsing

CVE-2025-15587 · Severity: info · CVSS 8.6 · Published 2026-03-16

Executive brief

Tinycontrol power distribution units and LAN controllers are affected by a security flaw that allows a user with low-level access to view the administrator's password. By accessing a hidden internal resource not available through the standard web interface, an attacker can gain full administrative control over the device. This could lead to unauthorized power management, sensor manipulation, or complete disruption of the connected infrastructure.

Technical details

A forced browsing (Direct Request) vulnerability exists in multiple Tinycontrol IoT devices, including tcPDU and LAN Controllers LK3.5, LK3.9, and LK4. The flaw (CWE-425) allows an authenticated user with low privileges to bypass graphical interface restrictions and directly access a specific resource that contains the administrator's password. This occurs because the device fails to properly enforce access control on all internal endpoints. An attacker on the local network with basic user credentials can exploit this to escalate privileges to administrator. The issue has been addressed in firmware versions 1.36 (tcPDU), 1.67 (LK3.5), 1.75 (LK3.9), and 1.38 (LK4) by implementing a unified authentication system and proper resource separation.

Affected products

  • tinycontrol tcPDU before 1.36
  • tinycontrol LAN Controller LK3.5 before 1.67 (hardware versions 3.5, 3.6, 3.7, 3.8)
  • tinycontrol LAN Controller LK3.9 before 1.75 (hardware version 3.9)
  • tinycontrol LAN Controller LK4 before 1.38 (hardware version 4.0)

Timeline

  • 2026-01-13: patched: Firmware updates released for LK3.5 and LK3.9
  • 2026-03-16: disclosed: Vulnerability disclosed by CERT Polska

References

Related threats