CVE-2026-82712: Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tycon Systems TPDIN-Monitor-WEB3to a version that resolves this vulnerability.Fixed in 2.4.2 - Compensating control
Mitigate the cross-site request forgery risk affecting Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior by preventing/limiting attacker ability to perform state-changing operations via CSRF until units are upgraded to v2.4.2.
Event History
Frequently Asked Questions
Which device versions need remediation?
TPDIN-Monitor-WEB3 versions 2.2.9 and earlier are affected. The references include firmware files identified as version 2.4.2, but the provided data does not explicitly state that this version fixes the issue.
What must an attacker do to exploit this issue?
The attacker must cause a user to interact with a malicious request, as indicated by the required user interaction in the severity vector. No attacker privileges are required, and the vulnerability can be exploited over the network.
What is the potential impact of a successful attack?
A successful CSRF attack can perform state-changing operations on the device. The provided severity vector indicates high potential impact to confidentiality, integrity, and availability.