Description
The Tycon Systems TPDIN-Monitor-WEB2
ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.
Published: 2026-07-24
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted Device Management
Action: Firmware Update
AI Analysis

Impact

The Tycon Systems TPDIN‑Monitor‑WEB2 unit ships with no HTTP credentials configured on firmware 2.4.4 and earlier. Because the web management interface is served without any authentication, an attacker who can reach the device’s network port gains full administrative control. The attacker can manipulate power relays, trigger reboots, reconfigure remote‑access services, and modify network settings, potentially disrupting infrastructure or causing physical damage to the equipment.

Affected Systems

Affected units are Tycon Systems TPDIN‑Monitor‑WEB2 devices running firmware version 2.4.4 or older. The vulnerability arises when the device is left in its default, unconfigured state; any installed instance that has not applied the latest firmware or set administrative credentials is at risk. Units exposed to the public internet or even a local network segment without proper segmentation are especially vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 9.3, placing it in the Critical range. The EPSS score is less than 1 %, indicating a low overall exploitation probability, and it is not listed in CISA’s KEV catalog. The likely attack vector is network-based; an adversary only needs legitimate network access to the device’s HTTP port. If exploited, the attacker can obtain unrestricted control over critical device functions, leading to denial of service or physical damage.

Generated by OpenCVE AI on September 4, 2026 at 23:49 UTC.

Remediation

Vendor Solution

Tycon Systems has released firmware 2.4.5, which resolves this vulnerability by requiring an administrator username and password to be set before the web interface is served. Further inquiries can be directed to security@tyconsystems.com. Tycon Systems recommends setting an administrative username and strong password on the Network Configuration page and confirming in a private browser window that a login is required, for units still running firmware 2.4.4 or earlier. Repeat this after any factory reset. Tycon Systems recommends not exposing the web interface to the Internet, as it is HTTP only. The unit should be kept on a private network, behind a firewall or VPN.


OpenCVE Recommended Actions

  • Update the firmware to Tycon Systems release 2.4.5, which adds mandatory administrative username and password requirements for the web interface.
  • For devices still running 2.4.4 or earlier, set a strong administrative username and password on the Network Configuration page immediately after installation or a factory reset, and confirm that the web interface now requires login.
  • Keep the web UI restricted to a private network behind a firewall or VPN, and block any unnecessary inbound access to the HTTP port.

Generated by OpenCVE AI on September 4, 2026 at 23:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
References

Fri, 04 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment. The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.
Title Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel Tycon Systems TPDIN-Monitor-WEB2 Missing Authentication for Critical Function
Weaknesses CWE-306

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Tycon Systems
Tycon Systems tpdin-monitor-web2
Vendors & Products Tycon Systems
Tycon Systems tpdin-monitor-web2

Fri, 24 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.
Title Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tycon Systems Tpdin-monitor-web2
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-04T21:28:52.355Z

Reserved: 2026-07-13T18:17:10.040Z

Link: CVE-2026-61884

cve-icon Vulnrichment

Updated: 2026-07-27T14:32:57.239Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T22:16:50.963

Modified: 2026-09-04T22:17:17.723

Link: CVE-2026-61884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:00:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function