Description
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
Published: 2026-09-04
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access of Credentials
Action: Immediate Patch
AI Analysis

Impact

Tycon Systems TPDIN‑Monitor‑WEB3 firmware versions 2.2.9 and earlier contain hard‑coded credentials that can be used by an attacker to authenticate to the device without legitimate user input. This flaw enables unauthorized access to protected data and the credentials stored or managed by the device, potentially allowing an attacker to steal sensitive information or compromise the device’s management interface.

Affected Systems

Devices running Tycon Systems TPDIN‑Monitor‑WEB3 firmware 2.2.9 or earlier are affected. The vendor has released firmware version 2.4.2 to remediate the issue; all units can be upgraded either with the signed .tfw container or the Intel HEX file provided by the vendor.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity vulnerability. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. Based on the nature of the fix, the attack likely requires network access to the device’s management interface or physical access to the device. Once the default credentials are successfully used, an attacker can access the device’s sensitive data or credentials. The exploit does not appear to require additional privileges beyond authentication to the affected firmware, making the vulnerability readily exploitable in environments where default or hard‑coded credentials are still in use.

Generated by OpenCVE AI on September 4, 2026 at 22:50 UTC.

Remediation

Vendor Solution

Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2. Units already running v2.4.2, for subsequent updates (signed container):  https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):  https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs. For more information, contact Tycon Systems:  https://www.tyconsystems.com/contact


OpenCVE Recommended Actions

  • Upgrade all TPDIN‑Monitor‑WEB3 units to firmware version 2.4.2 following the vendor’s instructions. If direct upgrade is not possible, use the provided Intel HEX payload to perform the update.
  • After updating, reset all default credentials and enforce a strong password policy; disable unused management services if possible.
  • Implement network segmentation to isolate the management interface, and monitor log files for unauthorized login attempts.

Generated by OpenCVE AI on September 4, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Tycon Systems
Tycon Systems tpdin-monitor-web3
Vendors & Products Tycon Systems
Tycon Systems tpdin-monitor-web3

Fri, 04 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
Title Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tycon Systems Tpdin-monitor-web3
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-09T10:09:36.114Z

Reserved: 2026-09-01T17:01:04.754Z

Link: CVE-2026-77847

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T21:17:25.710

Modified: 2026-09-09T10:21:31.733

Link: CVE-2026-77847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:25:44Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials