ZeroHour
Product

TPDIN-Monitor-WEB3

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Tycon Systems TPDIN-Monitor-WEB3

CISA reports three flaws (hard-coded credentials, CSRF, missing authorization) in Tycon TPDIN-Monitor-WEB3 <=2.2.9 enabling MitM, credential theft, or device resets.

CISA published ICSA-26-246-08 for Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, covering CVE-2026-77847 (use of hard-coded credentials, CWE-798), CVE-2026-82712 (CSRF, CWE-352), and CVE-2026-82684 (missing authorization, CWE-862). Exploitation could enable man-in-the-middle attacks, factory resets, credential wiping, or extraction of system credentials, configurations, and flash contents; the CSRF issue scores CVSS 8.8. No public exploitation has been reported; CISA recommends isolating devices from business networks.

Related CVEs

  • Missing Authorization Flaw in Tycon Systems TPDIN-Monitor-WEB3 Exposes Credentials
    CVE-2026-82684 is a missing authorization flaw (CWE-862) in Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier, in which network-accessible functions of the device's monitoring interface do not properly enforce authorization checks. The CVSS 4.0 vector (AV:N, PR:L, UI:N) indicates it can be triggered over the network with at most low-level access and no user interaction. An attacker who exploits it can extract system credentials, device configuration data, or the contents of the device's flash memory, and harvested credentials could enable deeper access to the device. Anyone running TPDIN-Monitor-WEB3 at version 2.2.9 or prior is affected, typically in remote power monitoring and control deployments. There are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only about a 0.5% chance of exploitation in the next 30 days (39th percentile).
    · Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and priorniche
  • CSRF in Tycon Systems TPDIN-Monitor-WEB3 allows unauthorized device changes
    CVE-2026-82712 is a cross-site request forgery (CSRF) flaw in the embedded web interface of Tycon Systems TPDIN-Monitor-WEB3 firmware, affecting versions 2.2.9 and prior. To trigger it, an attacker must induce an authenticated user of the device's web UI to load attacker-controlled content (for example, a malicious web page visited in the same browser session), which then silently submits forged requests to the device. A successful attack lets the adversary perform state-changing operations on the device without the user's knowledge, such as altering its configuration; the CVSS 4.0 score of 8.6 (high) reflects high impact on the vulnerable system, though user interaction is required. Any deployment running TPDIN-Monitor-WEB3 firmware 2.2.9 or earlier is affected. There are currently no signs of exploitation: no known in-the-wild activity, no public proof of concept, it is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.
    · Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and priorniche
  • Hard-coded credentials in Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior
    TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain a use of hard-coded credential flaw (CWE-798), meaning a static, unchangeable credential is embedded in the product. An attacker positioned on an adjacent network segment (CVSS 4.0 attack vector: Adjacent) with no privileges and no user interaction can leverage the embedded credential to access the device and intercept sensitive information or credentials. The CVSS 4.0 vector shows the impact is limited to confidentiality (VC:H), with no integrity or availability loss to the vulnerable system or subsequent systems. Only deployments of Tycon Systems TPDIN-Monitor-WEB3 running version 2.2.9 or earlier are affected. There is currently no known exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
    · Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and priorniche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.