The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use.
The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.
—
Missing Authorization Flaw in Tycon Systems TPDIN-Monitor-WEB3 Exposes Credentials
CVE-2026-82684 is a missing authorization flaw (CWE-862) in Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier, in which network-accessible functions of the device's monitoring interface do not properly enforce authorization checks. The CVSS 4.0 vector (AV:N, PR:L, UI:N) indicates it can be triggered over the network with at most low-level access and no user interaction. An attacker who exploits it can extract system credentials, device configuration data, or the contents of the device's flash memory, and harvested credentials could enable deeper access to the device. Anyone running TPDIN-Monitor-WEB3 at version 2.2.9 or prior is affected, typically in remote power monitoring and control deployments. There are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only about a 0.5% chance of exploitation in the next 30 days (39th percentile).
· Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and priorniche
CSRF in Tycon Systems TPDIN-Monitor-WEB3 allows unauthorized device changes
CVE-2026-82712 is a cross-site request forgery (CSRF) flaw in the embedded web interface of Tycon Systems TPDIN-Monitor-WEB3 firmware, affecting versions 2.2.9 and prior. To trigger it, an attacker must induce an authenticated user of the device's web UI to load attacker-controlled content (for example, a malicious web page visited in the same browser session), which then silently submits forged requests to the device. A successful attack lets the adversary perform state-changing operations on the device without the user's knowledge, such as altering its configuration; the CVSS 4.0 score of 8.6 (high) reflects high impact on the vulnerable system, though user interaction is required. Any deployment running TPDIN-Monitor-WEB3 firmware 2.2.9 or earlier is affected. There are currently no signs of exploitation: no known in-the-wild activity, no public proof of concept, it is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.
· Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and priorniche
Hard-coded credentials in Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior
TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain a use of hard-coded credential flaw (CWE-798), meaning a static, unchangeable credential is embedded in the product. An attacker positioned on an adjacent network segment (CVSS 4.0 attack vector: Adjacent) with no privileges and no user interaction can leverage the embedded credential to access the device and intercept sensitive information or credentials. The CVSS 4.0 vector shows the impact is limited to confidentiality (VC:H), with no integrity or availability loss to the vulnerable system or subsequent systems. Only deployments of Tycon Systems TPDIN-Monitor-WEB3 running version 2.2.9 or earlier are affected. There is currently no known exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
· Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and priorniche
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
—