Missing Authorization Flaw in Tycon Systems TPDIN-Monitor-WEB3 Exposes Credentials
AI analysis
CVE-2026-82684 is a missing authorization flaw (CWE-862) in Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier, in which network-accessible functions of the device's monitoring interface do not properly enforce authorization checks. The CVSS 4.0 vector (AV:N, PR:L, UI:N) indicates it can be triggered over the network with at most low-level access and no user interaction. An attacker who exploits it can extract system credentials, device configuration data, or the contents of the device's flash memory, and harvested credentials could enable deeper access to the device. Anyone running TPDIN-Monitor-WEB3 at version 2.2.9 or prior is affected, typically in remote power monitoring and control deployments. There are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only about a 0.5% chance of exploitation in the next 30 days (39th percentile).
What to do: Update TPDIN-Monitor-WEB3 devices to a firmware version newer than 2.2.9 per Tycon Systems' advisory. Until patched, restrict the device's web interface to trusted management networks or VPN access and avoid exposing it directly to the internet. Because the flaw can expose stored credentials, rotate device and associated account passwords if internet-facing exposure is suspected.
Affected
| Tycon Systems TPDIN-Monitor-WEB3 | 2.2.9 and prior |
Estimated exposure
nichelikely hundreds to low thousands of deployed devices (no public install counts or scan data available) — TPDIN-Monitor-WEB3 is a specialized remote power-monitoring appliance from a small vendor, typically deployed at remote sites such as telecom/WISP installations rather than at mass scale, and no public install-count or internet-exposure…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.