# CVE-2025-15587

## Summary

- **CVE ID:** CVE-2025-15587
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-425
- **Published:** Mar 16, 2026
- **Last Modified:** Mar 16, 2026

## Description

Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an administrator's password by directly accessing a specific resource inaccessible via a graphical interface.

This issue has been fixed in firmware versions: 1.36 (for tcPDU), 1.67 (for LK3.5 - hardware versions: 3.5, 3.6, 3.7 and 3.8), 1.75 (for LK3.9 - hardware version 3.9) and 1.38 (for LK4 - hardware version 4.0).

## Affected Products

- tinycontrol — Lan Kontroler v3.5 (0)
- tinycontrol — LK3.9 (0)
- tinycontrol — LK4 (0)
- tinycontrol — tcPDU (0)

## References

- [CNA](https://cert.pl/en/posts/2026/03/CVE-2025-11500/)
- [CNA](https://tinycontrol.pl/en/archives/lan-controller-35/downloads/#firmware)
- [CNA](https://tinycontrol.pl/en/lk39/downloads/#firmware)
- [CNA](https://tinycontrol.pl/en/lk4/downloads/#firmware)
- [CNA](https://tinycontrol.pl/en/tcpdu/downloads/#firmware)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._