← Back to Feed

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

CVE-2026-61884CVE-2026-55985

September 3, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Missing Authentication for Critical Function, Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-61884 The device ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment. View CVE Details Affected Products Tycon Systems TPDIN-Monitor-WEB2 (Update A) Vendor:Tycon Systems Product Version:Tycon Systems TPDIN-Monitor-WEB2: <2.4.5 Product Status:known_affected Remediations Vendor fixTycon Systems has released firmware 2.4.5, which resolves this vulnerability by requiring an administrator username and password to be set before the web interface is served. Further inquiries can be directed to [email protected]. MitigationTycon Systems recommends setting an administrative username and strong password on the Network Configuration page and confirming in a private browser window that a login is required, for units still running firmware 2.4.4 or...

Key Takeaways

  • CISA published an updated advisory for Tycon Systems TPDIN-Monitor-WEB2 covering vulnerabilities that could let attackers access sensitive credentials, disrupt connected infrastructure, or manipulate physical equipment.
  • Successful exploitation of the TPDIN-Monitor-WEB2 flaws could create a physical safety risk, so operators should apply the vendor's update to affected units.
  • Organizations should review the CSAF advisory to identify affected TPDIN-Monitor-WEB2 versions and implement CISA's recommended mitigations and monitoring.
☕ Buy a Coffee