Impact
Tycon Systems TPDIN‑Monitor‑WEB3 firmware versions 2.2.9 and earlier contain hard‑coded credentials that can be used by an attacker to authenticate to the device without legitimate user input. This flaw enables unauthorized access to protected data and the credentials stored or managed by the device, potentially allowing an attacker to steal sensitive information or compromise the device’s management interface.
Affected Systems
Devices running Tycon Systems TPDIN‑Monitor‑WEB3 firmware 2.2.9 or earlier are affected. The vendor has released firmware version 2.4.2 to remediate the issue; all units can be upgraded either with the signed .tfw container or the Intel HEX file provided by the vendor.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity vulnerability. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. Based on the nature of the fix, the attack likely requires network access to the device’s management interface or physical access to the device. Once the default credentials are successfully used, an attacker can access the device’s sensitive data or credentials. The exploit does not appear to require additional privileges beyond authentication to the affected firmware, making the vulnerability readily exploitable in environments where default or hard‑coded credentials are still in use.
OpenCVE Enrichment