AI analysis
TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain a use of hard-coded credential flaw (CWE-798), meaning a static, unchangeable credential is embedded in the product. An attacker positioned on an adjacent network segment (CVSS 4.0 attack vector: Adjacent) with no privileges and no user interaction can leverage the embedded credential to access the device and intercept sensitive information or credentials. The CVSS 4.0 vector shows the impact is limited to confidentiality (VC:H), with no integrity or availability loss to the vulnerable system or subsequent systems. Only deployments of Tycon Systems TPDIN-Monitor-WEB3 running version 2.2.9 or earlier are affected. There is currently no known exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Upgrade TPDIN-Monitor-WEB3 to a firmware version later than 2.2.9 as soon as Tycon Systems publishes a fix, and watch for the ICS-CERT advisory. Until patched, restrict which network segments can reach the device's management interface, since exploitation requires adjacent-network access. Because the credential is hard-coded, it cannot be rotated, so limit exposure and verify no management or monitoring services from these devices are exposed beyond trusted segments.
Affected
| Tycon Systems TPDIN-Monitor-WEB3 | 2.2.9 and prior |
Estimated exposure
nicheunknown; plausibly in the low thousands of deployed devices — TPDIN-Monitor-WEB3 is a niche embedded remote power-monitoring appliance from a small vendor typically deployed one-per-site in remote power and network-infrastructure settings, and no public internet-scan or install counts exist for it.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.