Tycon Systems TPDIN-Monitor-WEB2

Plan PatchCVSS 9.8ICS-CERT ICSA-26-202-01Jul 21, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

TPDIN-Monitor-WEB2 contains improper authentication (CWE-288) and inadequate encryption of sensitive data (CWE-312). These vulnerabilities allow an unauthenticated network attacker to extract stored credentials and authentication tokens without logging in. Once obtained, these credentials can be used to access the device's management interface and modify configuration on connected power distribution and network infrastructure. Successful exploitation could disrupt services or create physical safety risks. The vendor did not respond to CISA coordination attempts.

What this means
What could happen
An attacker could read stored credentials and authentication tokens, then use them to access the device and connected infrastructure. Once in, they could alter power or network settings on connected equipment, disrupting critical services or creating physical safety hazards.
Who's at risk
Water utilities, electric cooperatives, and municipalities running Tycon Systems TPDIN-Monitor-WEB2 devices should be concerned. This device monitors power distribution and network equipment in telecom and remote terminal sites. Compromise puts critical communications and power control at risk.
How it could be exploited
An attacker on the network (or internet, if the web interface is exposed) sends requests to the TPDIN-Monitor-WEB2 web interface without credentials. The interface does not properly authenticate or encrypt sensitive data storage, allowing the attacker to retrieve credentials, API tokens, or session information. Using these credentials, the attacker logs in to the management interface and can modify configuration on any connected infrastructure.
Prerequisites
  • Network access to the TPDIN-Monitor-WEB2 web interface (port 80 or 443)
  • No valid user credentials required for initial credential extraction
remotely exploitableno authentication requiredlow complexityhigh CVSS (9.8)affects critical infrastructure monitoringvendor non-responsive to coordination
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
TPDIN-Monitor-WEB2: 2.3.92.3.9Fix available
Remediation & Mitigation
0/4
Do now
0/3
HOTFIXContact Tycon Systems to request availability of security patches or firmware updates for TPDIN-Monitor-WEB2 version 2.3.9
WORKAROUNDIf the TPDIN-Monitor-WEB2 web interface is exposed to the internet or untrusted networks, restrict access to the device by firewall rule—allow only from trusted engineering workstations or management subnets on port 80/443
HARDENINGChange default credentials on the TPDIN-Monitor-WEB2 device to unique, strong passwords and ensure no hardcoded credentials are stored in plaintext or weak encryption
Long-term hardening
0/1
HARDENINGSegment the TPDIN-Monitor-WEB2 on a separate VLAN or management network isolated from field devices (PLCs, RTUs) to limit lateral movement if credentials are compromised
API: /api/v1/advisories/edbffb33-11b8-4156-b276-538b542f242f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Tycon Systems TPDIN-Monitor-WEB2 | CVSS 9.8 - OTPulse