Tycon Systems TPDIN-Monitor-WEB3
September 3, 2026 · CISA (US-CERT) · Severity: CRITICAL
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabilities v3 8.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials, Cross-Site Request Forgery (CSRF), Missing Authorization Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-77847 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Use of Hard-coded Credential vulnerability. This could allow an attacker to intercept sensitive information or credentials. View CVE Details Affected Products Tycon Systems TPDIN-Monitor-WEB3 Vendor:Tycon Systems Product Version:Tycon Systems TPDIN-Monitor-WEB3: <=2.2.9 Product Status:known_affected Remediations Vendor fixTycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2. MitigationUnits already running v2.4.2, for subsequent updates (signed container): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw MitigationAll units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex MitigationA unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs. MitigationFor more information, contact Tycon...
Key Takeaways
- CISA published an advisory for Tycon Systems TPDIN-Monitor-WEB3 urging users to apply vendor patches and mitigations.
- Organizations using Tycon Systems TPDIN-Monitor-WEB3 should review CISA's advisory and apply security updates promptly.
- Active exploitation of vulnerabilities in Tycon Systems TPDIN-Monitor-WEB3 has been reported, making patching urgent for affected organizations.