CISA Flags Multiple Critical Vulnerabilities in Tycon Systems TPDIN-Monitor-WEB3
CISA has issued an advisory detailing three critical vulnerabilities in Tycon Systems TPDIN-Monitor-WEB3 devices, potentially leading to man-in-the-middle attacks and credential theft.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory highlighting significant security flaws affecting Tycon Systems TPDIN-Monitor-WEB3 devices running firmware version 2.2.9 and prior. These vulnerabilities, if exploited, could allow attackers to compromise the integrity and confidentiality of industrial control systems.
Three distinct vulnerabilities have been identified: CVE-2026-77847, CVE-2026-82712, and CVE-2026-82684. The first, a use of hard-coded credentials (CWE-798), allows an attacker to intercept sensitive information or credentials by exploiting pre-defined, insecurely stored credentials within the device's firmware. This vulnerability carries a CVSS score of 6.5 (MEDIUM).
CVE-2026-82712 addresses a Cross-Site Request Forgery (CSRF) vulnerability (CWE-352). This flaw could enable an attacker to trick a user into performing unintended actions on the TPDIN-Monitor-WEB3 device, potentially leading to unauthorized configuration changes or other state-altering operations. This vulnerability is rated as HIGH with a CVSS score of 8.8.
The third vulnerability, CVE-2026-82684, is a Missing Authorization flaw (CWE-862). Successful exploitation of this vulnerability could permit an attacker to bypass authorization checks, enabling them to extract system credentials, configurations, or sensitive data from the device's flash memory. This vulnerability is also rated HIGH, with a CVSS score of 8.1.
Successful exploitation of these combined vulnerabilities could result in a range of severe impacts, including man-in-the-middle (MitM) attacks, theft of sensitive information or credentials, and even a complete device reset or wiping of credentials. The devices are deployed worldwide across critical infrastructure sectors such as Critical Manufacturing and Energy.
Tycon Systems has responded by releasing firmware version 2.4.2 to address these issues. Users are strongly advised to update their TPDIN-Monitor-WEB3 devices to the latest firmware. The advisory provides specific instructions and download links for both signed container updates and legacy Intel HEX formats, noting that units running v2.2.9 require the .hex build for a direct update to v2.4.2.
CISA recommends that organizations minimize network exposure for all control system devices, ensuring they are not accessible from the internet. Isolating control system networks behind firewalls and using secure remote access methods like VPNs are also crucial defensive measures. Organizations should consult the advisory for detailed mitigation strategies and contact Tycon Systems for further assistance.
This advisory underscores the ongoing risks to industrial control systems and the importance of timely patching and robust network segmentation to protect critical infrastructure from cyber threats.