CISA advisories flag five vulnerabilities across Tycon Systems TPDIN-Monitor-WEB2 and WEB3 remote power monitors
Two CISA advisories dated 2026-09-03 cover five CVEs in Tycon Systems power-monitor products: TPDIN-Monitor-WEB2 firmware below 2.4.5 (CVE-2026-61884, CVSS 9.8, unauthenticated relay/reboot control when HTTP credentials are unset; CVE-2026-55985, CVSS 4.3,…
On 2026-09-03, CISA advisories addressed two Tycon Systems remote power-monitor products. For TPDIN-Monitor-WEB2 (advisory marked Update A), firmware below 2.4.5 is affected by CVE-2026-61884 (CVSS 9.8, CWE-306): on units left without configured HTTP credentials, any network attacker gains unauthenticated access to full device controls, including power relay management, reboots, and network changes, with physical safety risk. CVE-2026-55985 (CVSS 4.3) exposes stored system credentials in cleartext to authenticated dashboard users, potentially enabling compromise of other local systems. For TPDIN-Monitor-WEB3, advisory ICSA-26-246-08 covers versions 2.2.9 and prior with three flaws: CVE-2026-77847 (use of hard-coded credentials, CWE-798), CVE-2026-82712 (CSRF, CWE-352, CVSS 8.8, permitting state-changing operations on devices), and CVE-2026-82684 (missing authorization, CWE-862). Exploitation of the WEB3 flaws could enable man-in-the-middle attacks, factory resets, credential wiping, or extraction of system credentials, configurations, and flash contents. CISA reports no public exploitation for either advisory. Recommended mitigations are updating WEB2 to firmware 2.4.5 or later and restricting its internet exposure, and keeping WEB3 devices off the internet, behind firewalls, and isolated from business networks. The reports do not specify a fixed firmware version for WEB3.
- Two CISA advisories, both timestamped 2026-09-03T12:00:00.000Z, cover Tycon Systems TPDIN-Monitor-WEB2 and TPDIN-Monitor-WEB3.
- WEB2: CVE-2026-61884 (CVSS 9.8, CWE-306) allows unauthenticated network attackers to control power relays, trigger reboots, and change network settings on units without configured HTTP credentials; physical safety risk noted.
- WEB2: CVE-2026-55985 (CVSS 4.3) exposes stored system credentials in cleartext to authenticated dashboard users, enabling possible lateral compromise of other local systems.
- WEB2: Affected firmware is below 2.4.5; remediation is to update to firmware 2.4.5 or later and restrict device internet exposure.
- WEB3: Advisory ICSA-26-246-08 covers versions 2.2.9 and prior; the reports do not state a fixed version for WEB3.
- WEB3: CVE-2026-77847 (hard-coded credentials, CWE-798), CVE-2026-82712 (CSRF, CWE-352, CVSS 8.8, permits state-changing operations), and CVE-2026-82684 (missing authorization, CWE-862).
- WEB3 impact: man-in-the-middle attacks, factory resets, credential wiping, or extraction of system credentials, configurations, and flash contents.
- No public exploitation has been reported to CISA for either the WEB2 or WEB3 vulnerabilities.
Coverage timelineoldest first · each row is one article
- · 12d agoTycon Systems TPDIN-Monitor-WEB3
CISA Advisories· 30
CISA reports three flaws (hard-coded credentials, CSRF, missing authorization) in Tycon TPDIN-Monitor-WEB3 <=2.2.9 enabling MitM, credential theft, or device resets.
- · 12d agoTycon Systems TPDIN-Monitor-WEB2 (Update A)
CISA Advisories· 33
CISA details CVE-2026-61884 (CVSS 9.8) in Tycon Systems TPDIN-Monitor-WEB2: unauthenticated access to power relays when credentials are unset; fixed in 2.4.5.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-55985 | The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network. NVD description · AI analysis pending | 5.3 | <1% | — | — | ||
| CVE-2026-61884 | The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment. NVD description · AI analysis pending | 9.3 | <1% | — | — | ||
| CVE-2026-77847 | Hard-coded credentials in Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain a use of hard-coded credential flaw (CWE-798), meaning a static, unchangeable credential is embedded in the product. An attacker positioned on an adjacent network segment (CVSS 4.0 attack vector: Adjacent) with no privileges and no user interaction can leverage the embedded credential to access the device and intercept sensitive information or credentials. The CVSS 4.0 vector shows the impact is limited to confidentiality (VC:H), with no integrity or availability loss to the vulnerable system or subsequent systems. Only deployments of Tycon Systems TPDIN-Monitor-WEB3 running version 2.2.9 or earlier are affected. There is currently no known exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days. Do: Upgrade TPDIN-Monitor-WEB3 to a firmware version later than 2.2.9 as soon as Tycon Systems publishes a fix, and watch for the ICS-CERT advisory. Until patched, restrict which network segments can reach the device's management interface, since exploitation requires adjacent-network access. Because the credential is hard-coded, it cannot be rotated, so limit exposure and verify no management or monitoring services from these devices are exposed beyond trusted segments. | 7.1 | <1% |
| nicheunknown; plausibly in the low thousands of deployed devices | ||
| CVE-2026-82684 | Missing Authorization Flaw in Tycon Systems TPDIN-Monitor-WEB3 Exposes Credentials CVE-2026-82684 is a missing authorization flaw (CWE-862) in Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier, in which network-accessible functions of the device's monitoring interface do not properly enforce authorization checks. The CVSS 4.0 vector (AV:N, PR:L, UI:N) indicates it can be triggered over the network with at most low-level access and no user interaction. An attacker who exploits it can extract system credentials, device configuration data, or the contents of the device's flash memory, and harvested credentials could enable deeper access to the device. Anyone running TPDIN-Monitor-WEB3 at version 2.2.9 or prior is affected, typically in remote power monitoring and control deployments. There are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only about a 0.5% chance of exploitation in the next 30 days (39th percentile). Do: Update TPDIN-Monitor-WEB3 devices to a firmware version newer than 2.2.9 per Tycon Systems' advisory. Until patched, restrict the device's web interface to trusted management networks or VPN access and avoid exposing it directly to the internet. Because the flaw can expose stored credentials, rotate device and associated account passwords if internet-facing exposure is suspected. | 8.6 | <1% |
| nichelikely hundreds to low thousands of deployed devices (no public install counts or scan data available) | ||
| CVE-2026-82712 | CSRF in Tycon Systems TPDIN-Monitor-WEB3 allows unauthorized device changes CVE-2026-82712 is a cross-site request forgery (CSRF) flaw in the embedded web interface of Tycon Systems TPDIN-Monitor-WEB3 firmware, affecting versions 2.2.9 and prior. To trigger it, an attacker must induce an authenticated user of the device's web UI to load attacker-controlled content (for example, a malicious web page visited in the same browser session), which then silently submits forged requests to the device. A successful attack lets the adversary perform state-changing operations on the device without the user's knowledge, such as altering its configuration; the CVSS 4.0 score of 8.6 (high) reflects high impact on the vulnerable system, though user interaction is required. Any deployment running TPDIN-Monitor-WEB3 firmware 2.2.9 or earlier is affected. There are currently no signs of exploitation: no known in-the-wild activity, no public proof of concept, it is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days. Do: Check the running firmware version in the device's web interface and upgrade TPDIN-Monitor-WEB3 to a release later than 2.2.9 (confirm the current fixed version with Tycon Systems). Until patched, restrict the management interface to trusted networks (avoid direct internet exposure) and avoid browsing untrusted sites in the same browser session while logged in to the device. | 8.6 | <1% |
| nichelikely on the order of a few thousand to low tens of thousands of deployed devices, mostly on management/internal networks (estimate; no public scan data) |