Security & Threat Intelligence · 21.07.2026, 21:21 UTC
Tycon Systems TPDIN-Monitor-WEB2
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories · CISA ICS Advisories ↗ |
| Veröffentlicht | 21.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-55985, CVE-2026-61884. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected:
TPDIN-Monitor-WEB2 2.3.9
CVSS Vendor Equipment Vulnerabilities
v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel, Cleartext Storage of Sensitive Information
Background
Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-61884
The web management interface of the affected device does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment. View CVE Details
Affected Products Tycon Systems TPDIN-Monitor-WEB2
Vendor:Tycon Systems Product Version:Tycon Systems TPDIN-Monitor-WEB2: 2.3.9 Product Status:known_affected
Remediations Vendor fixTycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems …