CVE-2025-11500
Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off (which is a default setting), an unauthenticated attacker on the local network can obtain usernames and encoded passwords for interface management portal by inspecting the HTTP response of the server when visiting the login page, which contains a JSON file with these details. Both normal and admin users credentials are exposed. This issue has been fixed in firmware versions: 1.36 (for tcPDU), 1.67 (for LK3.5 - hardware versions: 3.5, 3.6, 3.7 and 3.8), 1.75 (for LK3.9 - hardware version 3.9) and 1.38 (for LK4 - hardware version 4.0).
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 18
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1552.007Container APIcredential access90 % - Impacto secundario
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access75 %
Acceso a red adyacente (AV:A) sin autenticación requerida en dispositivos LAN (Tinycontrol). Exposición de credenciales codificadas en respuesta HTTP del portal de gestión, permitiendo acceso a cuentas de usuario y administrador.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (4)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-201, CWE-261
Referencias
- https://cert.pl/en/posts/2026/03/CVE-2025-11500/
- https://securitum.com/CVE-2025-11500
- https://tinycontrol.pl/en/archives/lan-controller-35/downloads/#firmware
- https://tinycontrol.pl/en/lk39/downloads/#firmware
- https://tinycontrol.pl/en/lk4/downloads/#firmware
- https://tinycontrol.pl/en/tcpdu/downloads/#firmware
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-11500",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-11500",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-03-16T16:24:05.827486Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "ADJACENT",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "cvd@cert.pl",
"affectedData": [
{
"vendor": "tinycontrol",
"product": "Lan Kontroler v3.5",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.67",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "tinycontrol",
"product": "LK3.9",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.75",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "tinycontrol",
"product": "LK4",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.38",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "tinycontrol",
"product": "tcPDU",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.36",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-16T14:17:54.113",
"references": [
{
"url": "https://cert.pl/en/posts/2026/03/CVE-2025-11500/",
"source": "cvd@cert.pl"
},
{
"url": "https://securitum.com/CVE-2025-11500",
"source": "cvd@cert.pl"
},
{
"url": "https://tinycontrol.pl/en/archives/lan-controller-35/downloads/#firmware",
"source": "cvd@cert.pl"
},
{
"url": "https://tinycontrol.pl/en/lk39/downloads/#firmware",
"source": "cvd@cert.pl"
},
{
"url": "https://tinycontrol.pl/en/lk4/downloads/#firmware",
"source": "cvd@cert.pl"
},
{
"url": "https://tinycontrol.pl/en/tcpdu/downloads/#firmware",
"source": "cvd@cert.pl"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"description": [
{
"lang": "en",
"value": "CWE-201"
},
{
"lang": "en",
"value": "CWE-261"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off (which is a default setting), an unauthenticated attacker on the local network can obtain usernames and encoded passwords for interface management portal by inspecting the HTTP response of the server when visiting the login page, which contains a JSON file with these details. Both normal and admin users credentials are exposed. \nThis issue has been fixed in firmware versions: 1.36 (for tcPDU), 1.67 (for LK3.5 - hardware versions: 3.5, 3.6, 3.7 and 3.8), 1.75 (for LK3.9 - hardware version 3.9) and 1.38 (for LK4 - hardware version 4.0)."
},
{
"lang": "es",
"value": "Los dispositivos Tinycontrol como tcPDU y los controladores LAN LK3.5, LK3.9 y LK4 tienen dos mecanismos de autenticación separados: uno únicamente para la gestión de la interfaz y otro para proteger todos los demás recursos del servidor. Cuando este último está desactivado (lo cual es una configuración predeterminada), un atacante no autenticado en la red local puede obtener nombres de usuario y contraseñas codificadas para el portal de gestión de la interfaz al inspeccionar la respuesta HTTP del servidor cuando se visita la página de inicio de sesión, la cual contiene un archivo JSON con estos detalles. Las credenciales de usuarios normales y administradores quedan expuestas.\nEste problema ha sido solucionado en las versiones de firmware: 1.36 (para tcPDU), 1.67 (para LK3.5 - versiones de hardware: 3.5, 3.6, 3.7 y 3.8), 1.75 (para LK3.9 - versión de hardware 3.9) y 1.38 (para LK4 - versión de hardware 4.0)."
}
],
"lastModified": "2026-06-17T08:30:35.007",
"sourceIdentifier": "cvd@cert.pl"
}