VYPR

TPDIN-Monitor-WEB2

by Tycon Systems

CVEs (5)

  • CVE-2026-61884CriJul 24, 2026
    risk 0.64cvss 9.8epss 0.01

    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and…

  • CVE-2026-82712HigSep 4, 2026
    risk 0.57cvss 8.8epss

    Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

  • CVE-2026-82684HigSep 4, 2026
    risk 0.53cvss 8.1epss

    Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.

  • CVE-2026-77847MedSep 4, 2026
    risk 0.42cvss 6.5epss

    Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.

  • CVE-2026-55985MedJul 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these…