ZeroHour

CVE-2026-82684

niche

Missing Authorization Flaw in Tycon Systems TPDIN-Monitor-WEB3 Exposes Credentials

CVSS 4.0
8.6 high
EPSS
<1%p39
Published
()
Modified
AI analysis

CVE-2026-82684 is a missing authorization flaw (CWE-862) in Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier, in which network-accessible functions of the device's monitoring interface do not properly enforce authorization checks. The CVSS 4.0 vector (AV:N, PR:L, UI:N) indicates it can be triggered over the network with at most low-level access and no user interaction. An attacker who exploits it can extract system credentials, device configuration data, or the contents of the device's flash memory, and harvested credentials could enable deeper access to the device. Anyone running TPDIN-Monitor-WEB3 at version 2.2.9 or prior is affected, typically in remote power monitoring and control deployments. There are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only about a 0.5% chance of exploitation in the next 30 days (39th percentile).

What to do: Update TPDIN-Monitor-WEB3 devices to a firmware version newer than 2.2.9 per Tycon Systems' advisory. Until patched, restrict the device's web interface to trusted management networks or VPN access and avoid exposing it directly to the internet. Because the flaw can expose stored credentials, rotate device and associated account passwords if internet-facing exposure is suspected.

Affected
Tycon Systems TPDIN-Monitor-WEB32.2.9 and prior
Estimated exposure
nichelikely hundreds to low thousands of deployed devices (no public install counts or scan data available) — TPDIN-Monitor-WEB3 is a specialized remote power-monitoring appliance from a small vendor, typically deployed at remote sites such as telecom/WISP installations rather than at mass scale, and no public install-count or internet-exposure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Tycon Systems TPDIN-Monitor-WEB3

CISA reports three flaws (hard-coded credentials, CSRF, missing authorization) in Tycon TPDIN-Monitor-WEB3 <=2.2.9 enabling MitM, credential theft, or device resets.

CISA published ICSA-26-246-08 for Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, covering CVE-2026-77847 (use of hard-coded credentials, CWE-798), CVE-2026-82712 (CSRF, CWE-352), and CVE-2026-82684 (missing authorization, CWE-862). Exploitation could enable man-in-the-middle attacks, factory resets, credential wiping, or extraction of system credentials, configurations, and flash contents; the CSRF issue scores CVSS 8.8. No public exploitation has been reported; CISA recommends isolating devices from business networks.