Impact
The vulnerability resides in the web management interface of Tycon Systems TPDIN‑Monitor‑WEB2. An authenticated user can view a configuration page that displays system credentials in cleartext. These credentials can be used to compromise other devices on the local network, potentially enabling lateral movement and further damage to the network infrastructure. The likely attack vector is a legitimate authenticated session to the administrative dashboard, which could be obtained by an insider or a compromised account.
Affected Systems
Tycon Systems – TPDIN‑Monitor‑WEB2. No specific version data is provided; the vulnerability potentially affects all installations of this product.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score of less than 1% suggests exploitation is unlikely but still possible in a targeted environment. The vulnerability is not listed in the CISA KEV catalog. Once the credentials are exposed, an attacker with network access could gain unauthorized privileges on other local systems.
OpenCVE Enrichment