Impact
The Tycon Systems TPDIN‑Monitor‑WEB2 web management interface fails to perform server‑side validation of credentials during the login process. An attacker can submit empty values for both the username and password fields, causing the system to treat the request as authenticated and establish a full administrative session. This allows the attacker to control device functions such as power relay management, device reboot, remote access service configuration, and network settings, potentially disrupting the connected infrastructure or causing physical damage.
Affected Systems
Tycon Systems TPDIN‑Monitor‑WEB2. No specific version information is supplied in the advisory; all deployed instances should be verified against the vendor’s firmware releases.
Risk and Exploitability
The CVSS score of 9.3 categorizes this vulnerability as Critical, while the EPSS score of less than 1% indicates a low probability of exploitation at any given time. The vulnerability is not listed in CISA’s KEV catalog. Nevertheless, if an attacker can reach the device’s web interface, the lack of credential validation means an unauthenticated actor can gain full administrative privileges, manipulate hardware controls, reboot the system, alter network configurations, or disable remote services, potentially disrupting operations or inflicting physical harm.
OpenCVE Enrichment