CVE-2026-82712: Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery

Published Sep 4, 2026
·
Updated

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

Affected Software

1 affected component
Tycon Systems TPDIN-Monitor-WEB3<=2.2.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Tycon Systems TPDIN-Monitor-WEB3 to a version that resolves this vulnerability.

    Fixed in 2.4.2
  2. Compensating control

    Mitigate the cross-site request forgery risk affecting Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior by preventing/limiting attacker ability to perform state-changing operations via CSRF until units are upgraded to v2.4.2.

Event History

Sep 4, 2026
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which device versions need remediation?

TPDIN-Monitor-WEB3 versions 2.2.9 and earlier are affected. The references include firmware files identified as version 2.4.2, but the provided data does not explicitly state that this version fixes the issue.

2

What must an attacker do to exploit this issue?

The attacker must cause a user to interact with a malicious request, as indicated by the required user interaction in the severity vector. No attacker privileges are required, and the vulnerability can be exploited over the network.

3

What is the potential impact of a successful attack?

A successful CSRF attack can perform state-changing operations on the device. The provided severity vector indicates high potential impact to confidentiality, integrity, and availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203