CVE-2026-77847: Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tycon Systems TPDIN-Monitor-WEB3to a version that resolves this vulnerability.Fixed in 2.4.2 - Operational
For units currently running v2.2.9 (legacy Intel HEX), install the Intel HEX artifact for TPDIN-Monitor-WEB3 Firmware v2.4.2 (TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex) because the signed .tfw container cannot be read by a v2.2.9 updater that accepts only Intel HEX.
Event History
Frequently Asked Questions
What level of network access does an attacker need to exploit this issue?
The attack vector is adjacent network access. Exploitation does not require prior privileges or user interaction.
How can I determine whether a device is affected?
Devices running TPDIN-Monitor-WEB3 version 2.2.9 or earlier are affected. Confirm the firmware or product version installed on each device.
What is the primary security impact?
An attacker could intercept sensitive information or credentials. The reported impact is high confidentiality impact, with no reported integrity or availability impact.