Impact
The Tycon Systems TPDIN‑Monitor‑WEB2 unit ships with no HTTP credentials configured on firmware 2.4.4 and earlier. Because the web management interface is served without any authentication, an attacker who can reach the device’s network port gains full administrative control. The attacker can manipulate power relays, trigger reboots, reconfigure remote‑access services, and modify network settings, potentially disrupting infrastructure or causing physical damage to the equipment.
Affected Systems
Affected units are Tycon Systems TPDIN‑Monitor‑WEB2 devices running firmware version 2.4.4 or older. The vulnerability arises when the device is left in its default, unconfigured state; any installed instance that has not applied the latest firmware or set administrative credentials is at risk. Units exposed to the public internet or even a local network segment without proper segmentation are especially vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 9.3, placing it in the Critical range. The EPSS score is less than 1 %, indicating a low overall exploitation probability, and it is not listed in CISA’s KEV catalog. The likely attack vector is network-based; an adversary only needs legitimate network access to the device’s HTTP port. If exploited, the attacker can obtain unrestricted control over critical device functions, leading to denial of service or physical damage.
OpenCVE Enrichment