ZeroHour

CVE-2026-77847

niche

Hard-coded credentials in Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior

CVSS 4.0
7.1 high
EPSS
<1%p26
Published
()
Modified
AI analysis

TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain a use of hard-coded credential flaw (CWE-798), meaning a static, unchangeable credential is embedded in the product. An attacker positioned on an adjacent network segment (CVSS 4.0 attack vector: Adjacent) with no privileges and no user interaction can leverage the embedded credential to access the device and intercept sensitive information or credentials. The CVSS 4.0 vector shows the impact is limited to confidentiality (VC:H), with no integrity or availability loss to the vulnerable system or subsequent systems. Only deployments of Tycon Systems TPDIN-Monitor-WEB3 running version 2.2.9 or earlier are affected. There is currently no known exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Upgrade TPDIN-Monitor-WEB3 to a firmware version later than 2.2.9 as soon as Tycon Systems publishes a fix, and watch for the ICS-CERT advisory. Until patched, restrict which network segments can reach the device's management interface, since exploitation requires adjacent-network access. Because the credential is hard-coded, it cannot be rotated, so limit exposure and verify no management or monitoring services from these devices are exposed beyond trusted segments.

Affected
Tycon Systems TPDIN-Monitor-WEB32.2.9 and prior
Estimated exposure
nicheunknown; plausibly in the low thousands of deployed devices — TPDIN-Monitor-WEB3 is a niche embedded remote power-monitoring appliance from a small vendor typically deployed one-per-site in remote power and network-infrastructure settings, and no public internet-scan or install counts exist for it.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.

Weakness
CWE-798
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Tycon Systems TPDIN-Monitor-WEB3

CISA reports three flaws (hard-coded credentials, CSRF, missing authorization) in Tycon TPDIN-Monitor-WEB3 <=2.2.9 enabling MitM, credential theft, or device resets.

CISA published ICSA-26-246-08 for Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, covering CVE-2026-77847 (use of hard-coded credentials, CWE-798), CVE-2026-82712 (CSRF, CWE-352), and CVE-2026-82684 (missing authorization, CWE-862). Exploitation could enable man-in-the-middle attacks, factory resets, credential wiping, or extraction of system credentials, configurations, and flash contents; the CSRF issue scores CVSS 8.8. No public exploitation has been reported; CISA recommends isolating devices from business networks.