PT-2026-25662 · Tinycontrol · Lk3.9+3

CVE-2025-15587

·

Publicado

2026-03-16

·

Atualizado

2026-03-16

CVSS v4.0

8.6

Alta

VetorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tinycontrol tcPDU versions prior to 1.36 Tinycontrol LK3.5 versions prior to 1.67 Tinycontrol LK3.9 versions prior to 1.75 Tinycontrol LK4 versions prior to 1.38
Description Tinycontrol devices, including tcPDU and LAN Controllers LK3.5, LK3.9, and LK4, permit a user with limited privileges to obtain an administrator's password by directly accessing a resource that is not available through the standard graphical interface.
Recommendations Update tcPDU to firmware version 1.36 or later. Update LK3.5 to firmware version 1.67 or later. Update LK3.9 to firmware version 1.75 or later. Update LK4 to firmware version 1.38 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15587

Produtos afetados

Lk3.9
Lk4
Lan Kontroler V3.5
Tcpdu