CVE-2026-61884: Tycon Systems TPDIN-Monitor-WEB2 Missing Authentication for Critical Function
The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tycon Systems TPDIN-Monitor-WEB2to a version that resolves this vulnerability.Fixed in 2.4.5 - Configuration
On the Network Configuration page, set an administrator username and strong password so that login is required for the HTTP web management interface.
TPDIN-Monitor-WEB2 web management interface Administrator username and password = Set an administrator username and strong password (before the web interface is served) - Configuration
Keep the web interface off the Internet (it is HTTP only). Instead, keep the unit on a private network behind a firewall or VPN.
TPDIN-Monitor-WEB2 web management interface Web interface exposure = Do not expose to the Internet - Operational
After any factory reset, repeat the administrative username/password configuration to ensure the unit no longer serves the web management interface without login (firmware 2.4.4 and earlier is affected when left unconfigured).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61884?
CVE-2026-61884 has a critical severity score of 9.8.
How do I fix CVE-2026-61884?
To fix CVE-2026-61884, ensure that the web management interface of Tycon Systems TPDIN-Monitor-WEB2 implements proper server-side validation of credentials.
What is the impact of CVE-2026-61884?
CVE-2026-61884 allows unauthenticated remote attackers to bypass authentication and gain unauthorized access to the system.
What type of vulnerability is CVE-2026-61884?
CVE-2026-61884 is an authentication bypass vulnerability.
Which product is affected by CVE-2026-61884?
CVE-2026-61884 affects the Tycon Systems TPDIN-Monitor-WEB2 web management interface.