CVE-2026-55985: Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information

Published Jul 24, 2026
·
Updated

The web management interface in Tycon Systems TPDIN-Monitor-WEB2

stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.

Affected Software

1 affected component
Tycon Systems TPDIN-Monitor-WEB2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Tycon Systems TPDIN-Monitor-WEB2 to a version that resolves this vulnerability.

    Fixed in 2.4.5
  2. Configuration

    Leave Telnet disabled unless required.

    Tycon Systems TPDIN-Monitor-WEB2 Telnet = disabled
  3. Configuration

    Change any factory-default SNMP community strings to non-default values.

    Tycon Systems TPDIN-Monitor-WEB2 SNMP community strings = change from factory-default
  4. Configuration

    If Telnet password is still set to shipped values, change it to a new password.

    Tycon Systems TPDIN-Monitor-WEB2 Telnet password = change from shipped factory-default
  5. Configuration

    Use a dedicated mail account for device alerts rather than an account also used for other sensitive purposes.

    Tycon Systems TPDIN-Monitor-WEB2 device alert mail account = dedicated account

Event History

Jul 24, 2026
CVE Published
via MITRE·09:37 PM
Data Sourced
via MITRE·09:37 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-55985?

The severity of CVE-2026-55985 is rated as medium with a score of 5.3.

2

How do I fix CVE-2026-55985?

To mitigate CVE-2026-55985, ensure that sensitive information is not stored or displayed in cleartext on any web interfaces.

3

What is the risk associated with CVE-2026-55985?

CVE-2026-55985 poses a risk as it allows authenticated users to access and read sensitive credentials displayed in cleartext.

4

Which software is affected by CVE-2026-55985?

CVE-2026-55985 affects the Tycon Systems TPDIN-Monitor-WEB2 software.

5

Who can exploit CVE-2026-55985?

Any authenticated user with access to the administrative dashboard can exploit CVE-2026-55985 to read the cleartext credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203