ZeroHour

CVE-2026-82712

niche

CSRF in Tycon Systems TPDIN-Monitor-WEB3 allows unauthorized device changes

CVSS 4.0
8.6 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-82712 is a cross-site request forgery (CSRF) flaw in the embedded web interface of Tycon Systems TPDIN-Monitor-WEB3 firmware, affecting versions 2.2.9 and prior. To trigger it, an attacker must induce an authenticated user of the device's web UI to load attacker-controlled content (for example, a malicious web page visited in the same browser session), which then silently submits forged requests to the device. A successful attack lets the adversary perform state-changing operations on the device without the user's knowledge, such as altering its configuration; the CVSS 4.0 score of 8.6 (high) reflects high impact on the vulnerable system, though user interaction is required. Any deployment running TPDIN-Monitor-WEB3 firmware 2.2.9 or earlier is affected. There are currently no signs of exploitation: no known in-the-wild activity, no public proof of concept, it is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Check the running firmware version in the device's web interface and upgrade TPDIN-Monitor-WEB3 to a release later than 2.2.9 (confirm the current fixed version with Tycon Systems). Until patched, restrict the management interface to trusted networks (avoid direct internet exposure) and avoid browsing untrusted sites in the same browser session while logged in to the device.

Affected
Tycon Systems TPDIN-Monitor-WEB32.2.9 and prior
Estimated exposure
nichelikely on the order of a few thousand to low tens of thousands of deployed devices, mostly on management/internal networks (estimate; no public scan data) — Tycon Systems is a niche supplier of remote power/network monitoring hardware typically deployed in small numbers per site (e.g., remote or WISP-style installations), and no public internet-exposure counts or install-base figures were…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

Weakness
CWE-352
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Tycon Systems TPDIN-Monitor-WEB3

CISA reports three flaws (hard-coded credentials, CSRF, missing authorization) in Tycon TPDIN-Monitor-WEB3 <=2.2.9 enabling MitM, credential theft, or device resets.

CISA published ICSA-26-246-08 for Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, covering CVE-2026-77847 (use of hard-coded credentials, CWE-798), CVE-2026-82712 (CSRF, CWE-352), and CVE-2026-82684 (missing authorization, CWE-862). Exploitation could enable man-in-the-middle attacks, factory resets, credential wiping, or extraction of system credentials, configurations, and flash contents; the CSRF issue scores CVSS 8.8. No public exploitation has been reported; CISA recommends isolating devices from business networks.