Description
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
Published: 2026-09-04
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check that allows an unauthenticated actor to read sensitive data from the TPDIN‑Monitor‑WEB3 device. An attacker can obtain system credentials, configuration files, or flash contents, potentially leading to full device takeover. This weakness is characterized as a missing authorization flaw (CWE‑862).

Affected Systems

Tycon Systems TPDIN‑Monitor‑WEB3 firmware versions 2.2.9 and all earlier releases are affected. The vulnerability exists in devices running these firmware images, regardless of the underlying hardware platform. Firmware v2.4.2 corrects the issue.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity, and the scope includes both confidentiality and integrity of device configuration data. Although the EPSS score is not available, the absence of a precise exploitation probability can be interpreted as an unknown likelihood, but the high CVSS suggests that an exploit could be feasible if the web interface is reachable. The vulnerability is not listed in the CISA KEV catalog, implying that no confirmed public exploits are known at this time. Exploitation would likely occur over the web interface, where authentication is bypassed, allowing an attacker to read privileged data and possibly further compromise the device.

Generated by OpenCVE AI on September 4, 2026 at 22:22 UTC.

Remediation

Vendor Solution

Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2. Units already running v2.4.2, for subsequent updates (signed container):  https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):  https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs. For more information, contact Tycon Systems:  https://www.tyconsystems.com/contact


OpenCVE Recommended Actions

  • Apply Tycon Systems firmware v2.4.2, using the signed .tfw or .hex update package compatible with the device.
  • If a device cannot be upgraded immediately, disable the TPDIN‑Monitor‑WEB3 web interface or restrict it to a trusted network segment to prevent unauthenticated access.
  • Replace the firmware only after verifying that the upgrade has been applied correctly and that audit logs no longer show the missing authorization condition.

Generated by OpenCVE AI on September 4, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
Title Tycon Systems TPDIN-Monitor-WEB3 Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-04T21:01:16.030Z

Reserved: 2026-09-01T17:01:04.761Z

Link: CVE-2026-82684

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T22:17:18.683

Modified: 2026-09-04T22:17:18.683

Link: CVE-2026-82684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:30:07Z

Weaknesses