Tycon Systems TPDIN-Monitor-WEB3
Plan PatchCVSS 8.8ICS-CERT ICSA-26-246-08Sep 3, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
The TPDIN-Monitor-WEB3 web-based monitoring interface in versions 2.2.9 and earlier contains hardcoded credentials (CWE-798), cross-site request forgery (CWE-352), and insufficient access controls (CWE-862). These flaws allow an attacker to perform man-in-the-middle attacks, trigger a factory reset, wipe stored credentials, or retrieve sensitive information from the monitoring system.
What this means
What could happen
An attacker could intercept monitoring data, reset the device to factory defaults, erase credentials, or access sensitive configuration and system information. This could compromise visibility into critical infrastructure operations and allow unauthorized reconfiguration of monitoring parameters.
Who's at risk
Water utilities, electric utilities, and other municipal infrastructure operators using Tycon Systems TPDIN-Monitor-WEB3 devices version 2.2.9 or earlier for remote monitoring and supervision of critical infrastructure equipment (power supplies, environmental monitoring, network infrastructure in remote sites).
How it could be exploited
An attacker with network access to the web interface could exploit hardcoded credentials to authenticate without a valid user account. Using CSRF techniques or direct API calls, the attacker could then trigger destructive actions like factory reset or credential wipe, or intercept unencrypted monitoring traffic to steal system data and configuration details.
Prerequisites
- Network access to the TPDIN-Monitor-WEB3 web interface (default HTTP/HTTPS ports)
- No valid user credentials required (hardcoded credentials present)
- No specific configuration or authentication bypass needed
remotely exploitableno authentication requiredlow complexityhardcoded credentialsaffects monitoring and control visibilitycan cause factory reset or data loss
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
TPDIN-Monitor-WEB3≤ 2.2.9Fix available
Remediation & Mitigation
0/4
Do now
0/2WORKAROUNDRestrict network access to the TPDIN-Monitor-WEB3 web interface to authorized monitoring workstations and management networks only using firewall rules
HARDENINGDisable or remove HTTP access and enforce HTTPS-only communication to the monitoring interface to reduce MitM attack surface
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate TPDIN-Monitor-WEB3 devices to firmware version 2.4.2 or later using the provided .hex update file (TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex for v2.2.9 devices)
Long-term hardening
0/1HARDENINGPlace TPDIN-Monitor-WEB3 devices on a network segment separate from operational control systems to limit lateral movement if compromised
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/59e2da67-9ade-4e27-a17e-a52c27783480Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.