CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Tycon Systems TPDIN-Monitor-WEB3

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5653

As cited

Copy frozen at (site build).

vulnerabilities

Tycon Systems TPDIN-Monitor-WEB3

Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain three vulnerabilities: hard-coded credentials (CVE-2026-77847), cross-site request forgery (CVE-2026-82712), and missing authorization (CVE-2026-82684). These flaws could enable attackers to perform man-in-the-middle attacks, trigger factory resets, wipe credentials, or access sensitive information. Tycon Systems has released firmware version 2.4.2 to address all three issues.

Why it matters: Organizations operating TPDIN-Monitor-WEB3 devices in critical manufacturing and energy sectors worldwide need to patch to firmware v2.4.2 immediately to prevent credential theft, unauthorized configuration changes, and information disclosure on internet-facing or network-accessible infrastructure monitoring equipment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Tycon Systems TPDIN-Monitor-WEB3

Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and earlier contain three vulnerabilities: hard-coded credentials (CVE-2026-77847), cross-site request forgery (CVE-2026-82712), and missing authorization (CVE-2026-82684). These flaws could enable attackers to perform man-in-the-middle attacks, trigger factory resets, wipe credentials, or access sensitive information. Tycon Systems has released firmware version 2.4.2 to address all three issues.

Why it matters: Organizations operating TPDIN-Monitor-WEB3 devices in critical manufacturing and energy sectors worldwide need to patch to firmware v2.4.2 immediately to prevent credential theft, unauthorized configuration changes, and information disclosure on internet-facing or network-accessible infrastructure monitoring equipment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary