IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Tycon Systems TPDIN-Monitor-WEB3

HIGH
CVSS 8.8
Date 2026-09-03T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.

// Vulnerabilities (3)

CVE ID CVSS Score Severity Description
CVE-2026-77847 6.5 medium
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Use of Hard-coded Credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
CVE-2026-82684 8.1 high
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
CVE-2026-82712 8.8 high
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Cross-Site Request Forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

// Remediations (5)

Mitigation: All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): ht
All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex
Mitigation: For more information, contact Tycon Systems https://www.tyconsystems.com/contact
For more information, contact Tycon Systems https://www.tyconsystems.com/contact
Mitigation: Units already running v2.4.2, for subsequent updates (signed container): https://firm.tyconsystems.c
Units already running v2.4.2, for subsequent updates (signed container): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw
Mitigation: A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no in
A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.
Patch: Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.
Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.

// References