ZeroHour
Vendor

Tycon Systems

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Tycon Systems TPDIN-Monitor-WEB3

CISA reports three flaws (hard-coded credentials, CSRF, missing authorization) in Tycon TPDIN-Monitor-WEB3 <=2.2.9 enabling MitM, credential theft, or device resets.

CISA published ICSA-26-246-08 for Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, covering CVE-2026-77847 (use of hard-coded credentials, CWE-798), CVE-2026-82712 (CSRF, CWE-352), and CVE-2026-82684 (missing authorization, CWE-862). Exploitation could enable man-in-the-middle attacks, factory resets, credential wiping, or extraction of system credentials, configurations, and flash contents; the CSRF issue scores CVSS 8.8. No public exploitation has been reported; CISA recommends isolating devices from business networks.

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

CISA details CVE-2026-61884 (CVSS 9.8) in Tycon Systems TPDIN-Monitor-WEB2: unauthenticated access to power relays when credentials are unset; fixed in 2.4.5.

CISA updated its advisory for Tycon Systems TPDIN-Monitor-WEB2 firmware below 2.4.5, covering two vulnerabilities. CVE-2026-61884 (CVSS 9.8, CWE-306) lets any network attacker reach full device controls, including power relay management and reboots, on units left without configured HTTP credentials. CVE-2026-55985 exposes stored system credentials in cleartext to authenticated dashboard users, enabling compromise of other local systems. No public exploitation has been reported to CISA.

Related CVEs

  • The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use.
    The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.
  • Missing Authorization Flaw in Tycon Systems TPDIN-Monitor-WEB3 Exposes Credentials
    CVE-2026-82684 is a missing authorization flaw (CWE-862) in Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier, in which network-accessible functions of the device's monitoring interface do not properly enforce authorization checks. The CVSS 4.0 vector (AV:N, PR:L, UI:N) indicates it can be triggered over the network with at most low-level access and no user interaction. An attacker who exploits it can extract system credentials, device configuration data, or the contents of the device's flash memory, and harvested credentials could enable deeper access to the device. Anyone running TPDIN-Monitor-WEB3 at version 2.2.9 or prior is affected, typically in remote power monitoring and control deployments. There are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only about a 0.5% chance of exploitation in the next 30 days (39th percentile).
    · Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and priorniche
  • CSRF in Tycon Systems TPDIN-Monitor-WEB3 allows unauthorized device changes
    CVE-2026-82712 is a cross-site request forgery (CSRF) flaw in the embedded web interface of Tycon Systems TPDIN-Monitor-WEB3 firmware, affecting versions 2.2.9 and prior. To trigger it, an attacker must induce an authenticated user of the device's web UI to load attacker-controlled content (for example, a malicious web page visited in the same browser session), which then silently submits forged requests to the device. A successful attack lets the adversary perform state-changing operations on the device without the user's knowledge, such as altering its configuration; the CVSS 4.0 score of 8.6 (high) reflects high impact on the vulnerable system, though user interaction is required. Any deployment running TPDIN-Monitor-WEB3 firmware 2.2.9 or earlier is affected. There are currently no signs of exploitation: no known in-the-wild activity, no public proof of concept, it is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.
    · Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and priorniche
  • Hard-coded credentials in Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior
    TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain a use of hard-coded credential flaw (CWE-798), meaning a static, unchangeable credential is embedded in the product. An attacker positioned on an adjacent network segment (CVSS 4.0 attack vector: Adjacent) with no privileges and no user interaction can leverage the embedded credential to access the device and intercept sensitive information or credentials. The CVSS 4.0 vector shows the impact is limited to confidentiality (VC:H), with no integrity or availability loss to the vulnerable system or subsequent systems. Only deployments of Tycon Systems TPDIN-Monitor-WEB3 running version 2.2.9 or earlier are affected. There is currently no known exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
    · Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and priorniche
  • The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible
    The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.