criticalOther

Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass and Cleartext Credential Storage

First seen Jul 22, 2026 · Updated Jul 22, 2026 · CVSS 9.8

ICSOTauthentication-bypasscritical-infrastructureCISA-advisorycleartext-credentials

Tycon Systems TPDIN-Monitor-WEB2 2.3.9, a power distribution monitoring device used in critical manufacturing, contains a critical authentication bypass (CVE-2026-61884, CVSS 9.8) allowing unauthenticated remote attackers to gain full administrative access by submitting empty login credentials. A secondary flaw (CVE-2026-55985) exposes system credentials in cleartext to any authenticated user, enabling lateral movement to other network systems. The vendor has not responded to CISA's coordination attempts, so no patch is currently available.

Technical Analysis

CVE-2026-61884 (CWE-288, CVSS v3.1 9.8/CVSS v4.0 9.3) stems from the device's web management interface failing to perform server-side validation of credentials; submitting empty username/password fields grants an unauthenticated attacker a valid administrative session with control over power relays, device reboot, remote access configuration, and network settings. CVE-2026-55985 (CWE-312, CVSS v3.1 4.3) allows cleartext exposure of system credentials on an authenticated configuration page, which can be harvested for further network compromise. Exploitation requires only network access to the device's web interface (AV:N, AC:L, PR:N for the primary flaw), making internet-exposed devices trivially exploitable. This is an OT/ICS device threat with physical safety implications (power relay manipulation) rather than a direct IT/software supply chain issue; there is no plausible direct impact to AI agent systems, LLM tool-use pipelines, or RAG infrastructure since this hardware is not typically part of AI agent toolchains.

Affected Systems

Tycon Systems TPDIN-Monitor-WEB2, version 2.3.9, and any deployments of this power distribution monitoring device with its web management interface accessible on a network, particularly if internet-facing.

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) reported; vulnerability is architectural/design-based rather than tied to a specific exploitation campaign.

Remediation Steps

  1. 1

    Isolate device from the internet

    Ensure TPDIN-Monitor-WEB2 devices are not directly accessible from the internet and are placed on isolated OT network segments.

  2. 2

    Network segmentation

    Place control system networks and remote devices behind firewalls, separated from business IT networks.

  3. 3

    Use secure remote access

    If remote access is required, use up-to-date VPN solutions rather than exposing the web interface directly.

  4. 4

    Contact vendor

    Since Tycon Systems has not responded to CISA, users should directly contact the vendor to request a security patch or mitigation guidance.

  5. 5

    Monitor and restrict access

    Restrict access to the administrative dashboard to trusted personnel only and monitor for unauthorized login attempts, including empty-credential login attempts.

  6. 6

    Report suspicious activity

    Follow internal incident response procedures and report any suspected malicious activity to CISA for tracking.

CVE / Advisory IDs

CVE-2026-61884CVE-2026-55985

Industries Most Exposed

Critical ManufacturingIndustrial Control SystemsEnergy/Power Infrastructure

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.