CVE-2026-55985: Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information
The web management interface in Tycon Systems TPDIN-Monitor-WEB2
stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tycon Systems TPDIN-Monitor-WEB2to a version that resolves this vulnerability.Fixed in 2.4.5 - Configuration
Leave Telnet disabled unless required.
Tycon Systems TPDIN-Monitor-WEB2 Telnet = disabled - Configuration
Change any factory-default SNMP community strings to non-default values.
Tycon Systems TPDIN-Monitor-WEB2 SNMP community strings = change from factory-default - Configuration
If Telnet password is still set to shipped values, change it to a new password.
Tycon Systems TPDIN-Monitor-WEB2 Telnet password = change from shipped factory-default - Configuration
Use a dedicated mail account for device alerts rather than an account also used for other sensitive purposes.
Tycon Systems TPDIN-Monitor-WEB2 device alert mail account = dedicated account
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55985?
The severity of CVE-2026-55985 is rated as medium with a score of 5.3.
How do I fix CVE-2026-55985?
To mitigate CVE-2026-55985, ensure that sensitive information is not stored or displayed in cleartext on any web interfaces.
What is the risk associated with CVE-2026-55985?
CVE-2026-55985 poses a risk as it allows authenticated users to access and read sensitive credentials displayed in cleartext.
Which software is affected by CVE-2026-55985?
CVE-2026-55985 affects the Tycon Systems TPDIN-Monitor-WEB2 software.
Who can exploit CVE-2026-55985?
Any authenticated user with access to the administrative dashboard can exploit CVE-2026-55985 to read the cleartext credentials.