Description
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
Published: 2026-09-04
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized state change via cross‑site request forgery
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a cross‑site request forgery flaw in Tycon Systems TPDIN‑Monitor‑WEB3 firmware versions 2.2.9 and earlier. An attacker who can cause a browser to issue a forged request or directly send HTTP requests to the web interface can trigger state‑changing operations on the device, such as changing configuration or functions, without the user’s permission. The flaw is identified as CWE‑352.

Affected Systems

Affected devices are Tycon Systems TPDIN‑Monitor‑WEB3 units running firmware v2.2.9 or older. The vulnerability exploits the web interface of the TPDIN‑Monitor‑WEB3 product, and no other Tycon Systems products are impacted according to the supplied CNA data.

Risk and Exploitability

Attack requires network access to the device’s web interface, and based on the description it is inferred that an authenticated or administrative session may be necessary for the attacker to execute state‑changing requests. The CVSS base score of 8.6 indicates a high severity with potential for full control over device state. EPSS data is not available. The vulnerability is not listed in the CISA KEV catalog, but given the high CVSS and the nature of the flaw, the risk is significant for exposed systems. The attacker does not need to compromise credentials if an existing session is hijacked or a user is tricked into sending a request.

Generated by OpenCVE AI on September 4, 2026 at 23:21 UTC.

Remediation

Vendor Solution

Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2. Units already running v2.4.2, for subsequent updates (signed container):  https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):  https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs. For more information, contact Tycon Systems:  https://www.tyconsystems.com/contact


OpenCVE Recommended Actions

  • Upgrade all TPDIN‑Monitor‑WEB3 devices to firmware v2.4.2, using the signed .tfw container for newer hardware or the .hex build for legacy units running v2.2.9.
  • Restrict access to the web interface by implementing firewall rules or network segmentation so that only trusted hosts or IP ranges can reach the device, thereby reducing the exposed attack surface.
  • If firmware upgrade is not immediately possible, configure the web server to require CSRF tokens or validate Origin/Referer headers for state‑changing requests, if the product supports such protection.

Generated by OpenCVE AI on September 4, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Tycon Systems
Tycon Systems tpdin-monitor-web3
Vendors & Products Tycon Systems
Tycon Systems tpdin-monitor-web3

Fri, 04 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
Title Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tycon Systems Tpdin-monitor-web3
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-07T11:17:27.526Z

Reserved: 2026-09-01T17:01:04.758Z

Link: CVE-2026-82712

cve-icon Vulnrichment

Updated: 2026-09-07T11:15:47.989Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T21:17:26.100

Modified: 2026-09-08T15:28:33.090

Link: CVE-2026-82712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:25:43Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)