42
57
47
47
57
42
57
42
57
57
Tycon Systems TPDIN-Monitor-WEB2 (Update A)
CISA details CVE-2026-61884 (CVSS 9.8) in Tycon Systems TPDIN-Monitor-WEB2: unauthenticated access to power relays when credentials are unset; fixed in 2.4.5.
CISA updated its advisory for Tycon Systems TPDIN-Monitor-WEB2 firmware below 2.4.5, covering two vulnerabilities. CVE-2026-61884 (CVSS 9.8, CWE-306) lets any network attacker reach full device controls, including power relay management and reboots, on units left without configured HTTP credentials. CVE-2026-55985 exposes stored system credentials in cleartext to authenticated dashboard users, enabling compromise of other local systems. No public exploitation has been reported to CISA.
33
57
57
42
57
57
57
57
42
57
42
57
57
42
42
57
57
57
42
57
57
42
47
42
42
47
57
60
42
42