Description
The web management interface of Tycon Systems TPDIN-Monitor-WEB2

 does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.
Published: 2026-07-24
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tycon Systems TPDIN‑Monitor‑WEB2 web management interface fails to perform server‑side validation of credentials during the login process. An attacker can submit empty values for both the username and password fields, causing the system to treat the request as authenticated and establish a full administrative session. This allows the attacker to control device functions such as power relay management, device reboot, remote access service configuration, and network settings, potentially disrupting the connected infrastructure or causing physical damage.

Affected Systems

Tycon Systems TPDIN‑Monitor‑WEB2. No specific version information is supplied in the advisory; all deployed instances should be verified against the vendor’s firmware releases.

Risk and Exploitability

The CVSS score of 9.3 categorizes this vulnerability as Critical, while the EPSS score of less than 1% indicates a low probability of exploitation at any given time. The vulnerability is not listed in CISA’s KEV catalog. Nevertheless, if an attacker can reach the device’s web interface, the lack of credential validation means an unauthenticated actor can gain full administrative privileges, manipulate hardware controls, reboot the system, alter network configurations, or disable remote services, potentially disrupting operations or inflicting physical harm.

Generated by OpenCVE AI on August 3, 2026 at 19:42 UTC.

Remediation

Vendor Workaround

Tycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems TPDIN-Monitor-WEB2 are encouraged to contact Tycon Systems and keep their systems up to date. https://www.tyconsystems.com/contact


OpenCVE Recommended Actions

  • Contact Tycon Systems support to request a security fix and verify that future releases contain the authentication bypass fix.
  • Until a patch is released, restrict access to the web management interface by applying firewall rules or network segmentation so that only trusted administrators can reach it.
  • Keep the device firmware and software up to date by regularly checking the vendor’s website and installing any released updates that may address the issue.

Generated by OpenCVE AI on August 3, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Tycon Systems
Tycon Systems tpdin-monitor-web2
Vendors & Products Tycon Systems
Tycon Systems tpdin-monitor-web2

Fri, 24 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.
Title Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tycon Systems Tpdin-monitor-web2
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-27T14:33:00.776Z

Reserved: 2026-07-13T18:17:10.040Z

Link: CVE-2026-61884

cve-icon Vulnrichment

Updated: 2026-07-27T14:32:57.239Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T22:16:50.963

Modified: 2026-07-30T14:12:18.697

Link: CVE-2026-61884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T19:45:07Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel