CVE-2026-61884: Tycon Systems TPDIN-Monitor-WEB2 Missing Authentication for Critical Function

Published Jul 24, 2026
·
Updated

The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.

Affected Software

1 affected component
Tycon Systems TPDIN-Monitor-WEB2<=2.4.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Tycon Systems TPDIN-Monitor-WEB2 to a version that resolves this vulnerability.

    Fixed in 2.4.5
  2. Configuration

    On the Network Configuration page, set an administrator username and strong password so that login is required for the HTTP web management interface.

    TPDIN-Monitor-WEB2 web management interface Administrator username and password = Set an administrator username and strong password (before the web interface is served)
  3. Configuration

    Keep the web interface off the Internet (it is HTTP only). Instead, keep the unit on a private network behind a firewall or VPN.

    TPDIN-Monitor-WEB2 web management interface Web interface exposure = Do not expose to the Internet
  4. Operational

    After any factory reset, repeat the administrative username/password configuration to ensure the unit no longer serves the web management interface without login (firmware 2.4.4 and earlier is affected when left unconfigured).

Event History

Jul 24, 2026
CVE Published
via MITRE·09:40 PM
Data Sourced
via MITRE·09:40 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-61884?

CVE-2026-61884 has a critical severity score of 9.8.

2

How do I fix CVE-2026-61884?

To fix CVE-2026-61884, ensure that the web management interface of Tycon Systems TPDIN-Monitor-WEB2 implements proper server-side validation of credentials.

3

What is the impact of CVE-2026-61884?

CVE-2026-61884 allows unauthenticated remote attackers to bypass authentication and gain unauthorized access to the system.

4

What type of vulnerability is CVE-2026-61884?

CVE-2026-61884 is an authentication bypass vulnerability.

5

Which product is affected by CVE-2026-61884?

CVE-2026-61884 affects the Tycon Systems TPDIN-Monitor-WEB2 web management interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203