ZeroHour
CISA Advisoriespublished ()ingested CISA
Part of a story covered by 2 sources: “CISA advisories flag five vulnerabilities across Tycon Systems TPDIN-Monitor-WEB2 and WEB3 remote power monitors” — merged summary and timeline →

Tycon Systems TPDIN-Monitor-WEB3

AI summary · glm-5.3-flash

CISA reports three flaws (hard-coded credentials, CSRF, missing authorization) in Tycon TPDIN-Monitor-WEB3 <=2.2.9 enabling MitM, credential theft, or device resets.

CISA published ICSA-26-246-08 for Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, covering CVE-2026-77847 (use of hard-coded credentials, CWE-798), CVE-2026-82712 (CSRF, CWE-352), and CVE-2026-82684 (missing authorization, CWE-862). Exploitation could enable man-in-the-middle attacks, factory resets, credential wiping, or extraction of system credentials, configurations, and flash contents; the CSRF issue scores CVSS 8.8. No public exploitation has been reported; CISA recommends isolating devices from business networks.

  • Three CVEs: hard-coded credentials (CVE-2026-77847), CSRF (CVE-2026-82712), missing authorization (CVE-2026-82684)
  • CSRF issue scores CVSS 8.8 and permits state-changing operations on devices
  • Exploitation can enable MitM, factory reset, credential wipe, or configuration and flash extraction
  • Keep devices off the internet and behind firewalls; no exploitation reported
OrganizationsCISA

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-77847
Hard-coded credentials in Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior

TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain a use of hard-coded credential flaw (CWE-798), meaning a static, unchangeable credential is embedded in the product. An attacker positioned on an adjacent network segment (CVSS 4.0 attack vector: Adjacent) with no privileges and no user interaction can leverage the embedded credential to access the device and intercept sensitive information or credentials. The CVSS 4.0 vector shows the impact is limited to confidentiality (VC:H), with no integrity or availability loss to the vulnerable system or subsequent systems. Only deployments of Tycon Systems TPDIN-Monitor-WEB3 running version 2.2.9 or earlier are affected. There is currently no known exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

Do: Upgrade TPDIN-Monitor-WEB3 to a firmware version later than 2.2.9 as soon as Tycon Systems publishes a fix, and watch for the ICS-CERT advisory. Until patched, restrict which network segments can reach the device's management interface, since exploitation requires adjacent-network access. Because the credential is hard-coded, it cannot be rotated, so limit exposure and verify no management or monitoring services from these devices are exposed beyond trusted segments.

7.1<1%
  • Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior
nicheunknown; plausibly in the low thousands of deployed devices
CVE-2026-82684
Missing Authorization Flaw in Tycon Systems TPDIN-Monitor-WEB3 Exposes Credentials

CVE-2026-82684 is a missing authorization flaw (CWE-862) in Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier, in which network-accessible functions of the device's monitoring interface do not properly enforce authorization checks. The CVSS 4.0 vector (AV:N, PR:L, UI:N) indicates it can be triggered over the network with at most low-level access and no user interaction. An attacker who exploits it can extract system credentials, device configuration data, or the contents of the device's flash memory, and harvested credentials could enable deeper access to the device. Anyone running TPDIN-Monitor-WEB3 at version 2.2.9 or prior is affected, typically in remote power monitoring and control deployments. There are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only about a 0.5% chance of exploitation in the next 30 days (39th percentile).

Do: Update TPDIN-Monitor-WEB3 devices to a firmware version newer than 2.2.9 per Tycon Systems' advisory. Until patched, restrict the device's web interface to trusted management networks or VPN access and avoid exposing it directly to the internet. Because the flaw can expose stored credentials, rotate device and associated account passwords if internet-facing exposure is suspected.

8.6<1%
  • Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior
nichelikely hundreds to low thousands of deployed devices (no public install counts or scan data available)
CVE-2026-82712
CSRF in Tycon Systems TPDIN-Monitor-WEB3 allows unauthorized device changes

CVE-2026-82712 is a cross-site request forgery (CSRF) flaw in the embedded web interface of Tycon Systems TPDIN-Monitor-WEB3 firmware, affecting versions 2.2.9 and prior. To trigger it, an attacker must induce an authenticated user of the device's web UI to load attacker-controlled content (for example, a malicious web page visited in the same browser session), which then silently submits forged requests to the device. A successful attack lets the adversary perform state-changing operations on the device without the user's knowledge, such as altering its configuration; the CVSS 4.0 score of 8.6 (high) reflects high impact on the vulnerable system, though user interaction is required. Any deployment running TPDIN-Monitor-WEB3 firmware 2.2.9 or earlier is affected. There are currently no signs of exploitation: no known in-the-wild activity, no public proof of concept, it is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

Do: Check the running firmware version in the device's web interface and upgrade TPDIN-Monitor-WEB3 to a release later than 2.2.9 (confirm the current fixed version with Tycon Systems). Until patched, restrict the management interface to trusted networks (avoid direct internet exposure) and avoid browsing untrusted sites in the same browser session while logged in to the device.

8.6<1%
  • Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior
nichelikely on the order of a few thousand to low tens of thousands of deployed devices, mostly on management/internal networks (estimate; no public scan data)
Full article629 words · extracted from cisa.gov · click to collapse

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.

The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:

  • TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684)
CVSS Vendor Equipment Vulnerabilities
v3 8.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials, Cross-Site Request Forgery (CSRF), Missing Authorization

Background

  • Critical Infrastructure Sectors: Critical Manufacturing, Energy
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: United States

Vulnerabilities

Expand All +

CVE-2026-77847

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Use of Hard-coded Credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.

View CVE Details


Affected Products

Tycon Systems TPDIN-Monitor-WEB3

Vendor:
Tycon Systems

Product Version:
Tycon Systems TPDIN-Monitor-WEB3: <=2.2.9

Product Status:
known_affected

Relevant CWE: CWE-798 Use of Hard-coded Credentials


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-82712

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Cross-Site Request Forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

View CVE Details


Affected Products

Tycon Systems TPDIN-Monitor-WEB3

Vendor:
Tycon Systems

Product Version:
Tycon Systems TPDIN-Monitor-WEB3: <=2.2.9

Product Status:
known_affected

Relevant CWE: CWE-352 Cross-Site Request Forgery (CSRF)


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
4.0 8.6 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-82684

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.

View CVE Details


Affected Products

Tycon Systems TPDIN-Monitor-WEB3

Vendor:
Tycon Systems

Product Version:
Tycon Systems TPDIN-Monitor-WEB3: <=2.2.9

Product Status:
known_affected

Relevant CWE: CWE-862 Missing Authorization


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
4.0 8.6 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Acknowledgments

  • Abdiwelli Guled reported these vulnerabilities to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.

Locate control system networks and remote devices behind firewalls and isolating them from business networks.

When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

Do not click web links or open attachments in unsolicited email messages.

Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.

Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.


Revision History

  • Initial Release Date: 2026-09-03
Date Revision Summary
2026-09-03 1 Initial Publication

Legal Notice and Terms of Use

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08