Back to Feed
VulnerabilitiesJul 21, 2026

Tycon Systems TPDIN-Monitor-WEB2

CISA releases advisory for critical authentication bypass in Tycon Systems TPDIN-Monitor-WEB2 2.3.9

Summary

CISA published an advisory for two critical vulnerabilities in Tycon Systems TPDIN-Monitor-WEB2 2.3.9, a web management interface used in critical manufacturing infrastructure. CVE-2026-61884 allows unauthenticated remote attackers to bypass authentication by submitting empty credentials, granting full administrative access to power relay management, device reboot, and network settings. CVE-2026-55985 exposes credentials in cleartext on the administrative dashboard. The vendor did not respond to CISA coordination attempts, and no public exploitation has been reported.

Full text

ICS Advisory Tycon Systems TPDIN-Monitor-WEB2 Release DateJuly 21, 2026 Alert CodeICSA-26-202-01 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected: TPDIN-Monitor-WEB2 2.3.9 CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel, Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-61884 The web management interface of the affected device does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment. View CVE Details Affected Products Tycon Systems TPDIN-Monitor-WEB2 Vendor:Tycon Systems Product Version:Tycon Systems TPDIN-Monitor-WEB2: 2.3.9 Product Status:known_affected Remediations Vendor fixTycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems TPDIN-Monitor-WEB2 are encouraged to contact Tycon Systems and keep their systems up to date.https://www.tyconsystems.com/contact Relevant CWE: CWE-288 Authentication Bypass Using an Alternate Path or Channel Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-55985 The device's web management interface stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network. View CVE Details Affected Products Tycon Systems TPDIN-Monitor-WEB2 Vendor:Tycon Systems Product Version:Tycon Systems TPDIN-Monitor-WEB2: 2.3.9 Product Status:known_affected Remediations Vendor fixTycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems TPDIN-Monitor-WEB2 are encouraged to contact Tycon Systems and keep their systems up to date.https://www.tyconsystems.com/contact Relevant CWE: CWE-312 Cleartext Storage of Sensitive Information Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N 4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Acknowledgments Abdiwelli Guled reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-07-21 Date Revision Summary 2026-07-21 1 Initial Publication Legal Notice and Terms of Use This product is provided subject to this Notification and this Privacy & Use policy. Tags Sector: Critical Manufacturing Sector Topics: Industrial Control System Vulnerabilities, Industrial Control Systems Please share your thoughts We recently updated our anonymous product survey; we welcome your feedback. Related Advisories Jul 21, 2026 ICS Advisory | ICSA-26-202-02 Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Jul 21, 2026 ICS Advisory | ICSA-26-202-10 Rockwell Automation Studio 5000 Logix Designer Jul 21, 2026 ICS Advisory | ICSA-26-202-03 Siemens Opcenter X Jul 21, 2026 ICS Advisory | ICSA-26-202-05 Siemens IAM Client

Indicators of Compromise

  • cve — CVE-2026-61884
  • cve — CVE-2026-55985

Entities

Tycon Systems (vendor)TPDIN-Monitor-WEB2 (product)Industrial Control Systems (ICS) (technology)