Impact
The vulnerability is a cross‑site request forgery flaw in Tycon Systems TPDIN‑Monitor‑WEB3 firmware versions 2.2.9 and earlier. An attacker who can cause a browser to issue a forged request or directly send HTTP requests to the web interface can trigger state‑changing operations on the device, such as changing configuration or functions, without the user’s permission. The flaw is identified as CWE‑352.
Affected Systems
Affected devices are Tycon Systems TPDIN‑Monitor‑WEB3 units running firmware v2.2.9 or older. The vulnerability exploits the web interface of the TPDIN‑Monitor‑WEB3 product, and no other Tycon Systems products are impacted according to the supplied CNA data.
Risk and Exploitability
Attack requires network access to the device’s web interface, and based on the description it is inferred that an authenticated or administrative session may be necessary for the attacker to execute state‑changing requests. The CVSS base score of 8.6 indicates a high severity with potential for full control over device state. EPSS data is not available. The vulnerability is not listed in the CISA KEV catalog, but given the high CVSS and the nature of the flaw, the risk is significant for exposed systems. The attacker does not need to compromise credentials if an existing session is hijacked or a user is tricked into sending a request.
OpenCVE Enrichment