As cited
Copy frozen at (site build).
vulnerabilities
Tycon Systems TPDIN-Monitor-WEB2
Tycon Systems TPDIN-Monitor-WEB2 version 2.3.9 contains two critical vulnerabilities: an authentication bypass (CVE-2026-61884) that allows unauthenticated attackers to gain administrative access by submitting empty credential fields, and a cleartext credential storage issue (CVE-2026-55985) that exposes system passwords to authenticated users. Tycon Systems did not respond to CISA coordination efforts, and exploitation could enable infrastructure disruption or physical equipment damage.
Why it matters: Organizations operating TPDIN-Monitor-WEB2 devices in critical manufacturing environments worldwide face immediate risk of unauthorized administrative access and credential compromise; update or isolate affected devices and contact the vendor for patches.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Tycon Systems TPDIN-Monitor-WEB2
Tycon Systems TPDIN-Monitor-WEB2 version 2.3.9 contains two critical vulnerabilities: an authentication bypass (CVE-2026-61884) that allows unauthenticated attackers to gain administrative access by submitting empty credential fields, and a cleartext credential storage issue (CVE-2026-55985) that exposes system passwords to authenticated users. Tycon Systems did not respond to CISA coordination efforts, and exploitation could enable infrastructure disruption or physical equipment damage.
Why it matters: Organizations operating TPDIN-Monitor-WEB2 devices in critical manufacturing environments worldwide face immediate risk of unauthorized administrative access and credential compromise; update or isolate affected devices and contact the vendor for patches.
- Source published
- First seen by Cybersecurity Tracker