Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass and Cleartext Credential Storage
First seen Jul 22, 2026 · Updated Jul 22, 2026 · CVSS 9.8
Tycon Systems TPDIN-Monitor-WEB2 2.3.9, a power distribution monitoring device used in critical manufacturing, contains a critical authentication bypass (CVE-2026-61884, CVSS 9.8) allowing unauthenticated remote attackers to gain full administrative access by submitting empty login credentials. A secondary flaw (CVE-2026-55985) exposes system credentials in cleartext to any authenticated user, enabling lateral movement to other network systems. The vendor has not responded to CISA's coordination attempts, so no patch is currently available.
Technical Analysis
CVE-2026-61884 (CWE-288, CVSS v3.1 9.8/CVSS v4.0 9.3) stems from the device's web management interface failing to perform server-side validation of credentials; submitting empty username/password fields grants an unauthenticated attacker a valid administrative session with control over power relays, device reboot, remote access configuration, and network settings. CVE-2026-55985 (CWE-312, CVSS v3.1 4.3) allows cleartext exposure of system credentials on an authenticated configuration page, which can be harvested for further network compromise. Exploitation requires only network access to the device's web interface (AV:N, AC:L, PR:N for the primary flaw), making internet-exposed devices trivially exploitable. This is an OT/ICS device threat with physical safety implications (power relay manipulation) rather than a direct IT/software supply chain issue; there is no plausible direct impact to AI agent systems, LLM tool-use pipelines, or RAG infrastructure since this hardware is not typically part of AI agent toolchains.
Affected Systems
Tycon Systems TPDIN-Monitor-WEB2, version 2.3.9, and any deployments of this power distribution monitoring device with its web management interface accessible on a network, particularly if internet-facing.
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) reported; vulnerability is architectural/design-based rather than tied to a specific exploitation campaign.
Remediation Steps
- 1
Isolate device from the internet
Ensure TPDIN-Monitor-WEB2 devices are not directly accessible from the internet and are placed on isolated OT network segments.
- 2
Network segmentation
Place control system networks and remote devices behind firewalls, separated from business IT networks.
- 3
Use secure remote access
If remote access is required, use up-to-date VPN solutions rather than exposing the web interface directly.
- 4
Contact vendor
Since Tycon Systems has not responded to CISA, users should directly contact the vendor to request a security patch or mitigation guidance.
- 5
Monitor and restrict access
Restrict access to the administrative dashboard to trusted personnel only and monitor for unauthorized login attempts, including empty-credential login attempts.
- 6
Report suspicious activity
Follow internal incident response procedures and report any suspected malicious activity to CISA for tracking.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.