CVE-2026-82684: Tycon Systems TPDIN-Monitor-WEB3 Missing Authorization
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tycon Systems TPDIN-Monitor-WEB3to a version that resolves this vulnerability.Fixed in 2.4.2 - Compensating control
For units using the v2.2.9 updater that accepts only Intel HEX (legacy Intel HEX), ensure the deployed units receive the Intel HEX artifact (TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex) because the signed .tfw container cannot be read by a v2.2.9 updater.
Event History
Frequently Asked Questions
Which deployments are affected?
Tycon Systems TPDIN-Monitor-WEB3 devices running version 2.2.9 or earlier are affected. Devices should be inventoried by product and firmware version to identify exposure.
What does an attacker need to exploit this issue?
The vulnerability is network-exploitable with low attack complexity and requires low privileges. No user interaction is required.
What could an attacker access?
Successful exploitation could allow extraction of system credentials, device configurations, or flash contents. The reported impact includes high confidentiality and integrity impact.