Impact
The vulnerability is a missing authorization check that allows an unauthenticated actor to read sensitive data from the TPDIN‑Monitor‑WEB3 device. An attacker can obtain system credentials, configuration files, or flash contents, potentially leading to full device takeover. This weakness is characterized as a missing authorization flaw (CWE‑862).
Affected Systems
Tycon Systems TPDIN‑Monitor‑WEB3 firmware versions 2.2.9 and all earlier releases are affected. The vulnerability exists in devices running these firmware images, regardless of the underlying hardware platform. Firmware v2.4.2 corrects the issue.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity, and the scope includes both confidentiality and integrity of device configuration data. Although the EPSS score is not available, the absence of a precise exploitation probability can be interpreted as an unknown likelihood, but the high CVSS suggests that an exploit could be feasible if the web interface is reachable. The vulnerability is not listed in the CISA KEV catalog, implying that no confirmed public exploits are known at this time. Exploitation would likely occur over the web interface, where authentication is bypassed, allowing an attacker to read privileged data and possibly further compromise the device.
OpenCVE Enrichment