Tycon Systems TPDIN-Monitor-WEB2 Vulnerable to Critical Authentication Bypass and Credential Exposure
CISA has issued an advisory for Tycon Systems TPDIN-Monitor-WEB2, detailing two critical vulnerabilities that could allow unauthenticated attackers to gain administrative access and expose system credentials.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory detailing two critical vulnerabilities affecting the Tycon Systems TPDIN-Monitor-WEB2 industrial control system device. The vulnerabilities, identified as CVE-2026-61884 and CVE-2026-55985, pose significant risks to critical manufacturing infrastructure and could lead to disruption, credential theft, and potential physical safety hazards.
CVE-2026-61884 is a critical authentication bypass vulnerability that allows unauthenticated remote attackers to gain administrative access to the device. The flaw lies in the web management interface's failure to perform server-side validation of credentials during the login process. By submitting empty values for both username and password fields, an attacker can bypass authentication and establish a full administrative session. This level of access enables control over power relay management, device reboots, remote access services, and network settings, potentially leading to infrastructure disruption or physical damage.
This vulnerability carries a CVSS v3.1 base score of 9.8, classifying it as critical. The attack vector is network-based (AV:N), requires no privileges (PR:N), and has low complexity (AC:L). Successful exploitation could lead to high confidentiality, integrity, and availability impacts (C:H/I:H/A:H).
The second vulnerability, CVE-2026-55985, involves the cleartext storage of sensitive information. The device's web management interface stores and displays system credentials in plain text on a specific configuration page accessible to authenticated users. Any attacker who gains even limited authenticated access to the administrative dashboard can easily read these credentials. This information could then be used to compromise other systems connected to the local network, expanding the attack surface.
CVE-2026-55985 has a CVSS v3.1 base score of 4.3, categorized as medium severity. While it requires authenticated access (PR:L), it still presents a risk of confidentiality loss (C:L) if an attacker can gain initial access to the system.
These vulnerabilities were reported to CISA by Abdiwelli Guled. Tycon Systems, headquartered in the United States, was contacted by CISA for coordination but did not respond. As a result, there is currently no vendor-provided patch or fix available for version 2.3.9 of the TPDIN-Monitor-WEB2.
CISA strongly recommends that users of the affected Tycon Systems TPDIN-Monitor-WEB2 devices take defensive measures. These include minimizing network exposure by ensuring devices are not accessible from the internet, locating control system networks behind firewalls, and isolating them from business networks. When remote access is necessary, more secure methods like Virtual Private Networks (VPNs) should be employed, ensuring VPNs and connected devices are kept up-to-date.
Organizations are urged to perform thorough impact analyses and risk assessments before implementing defensive measures. CISA also encourages the implementation of recommended cybersecurity strategies for proactive defense of Industrial Control Systems (ICS) assets, emphasizing defense-in-depth strategies. While no public exploitation has been reported to CISA at this time, the critical nature of these vulnerabilities warrants immediate attention and mitigation efforts.