Junglewise Threat Intelligence

CVE-2026-55985: Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Credentials

CVE-2026-55985 · Severity: medium · CVSS 4.3 · Published 2026-07-24

Executive brief

The Tycon Systems TPDIN-Monitor-WEB2, a device used for remote monitoring and control of power systems, contains a security flaw in its web management interface. The system stores and displays administrative credentials in plain text on a configuration page. This allows any user with basic access to the dashboard to see sensitive passwords, which could then be used to take full control of the device or other systems on the same network.

Technical details

A cleartext storage of sensitive information vulnerability (CWE-312) exists in the Tycon Systems TPDIN-Monitor-WEB2 web management interface. The application stores and displays system credentials in plain text on a specific configuration page. An attacker with low-privileged authenticated access to the administrative dashboard can view these credentials via the network. These credentials can be leveraged to escalate privileges on the device or facilitate lateral movement to other systems on the local network. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is confirmed.

Affected products

  • Tycon Systems TPDIN-Monitor-WEB2 2.3.9

Timeline

  • 2026-07-21: advisory: Initial publication by CISA (ICSA-26-202-01)
  • 2026-07-24: disclosed: CVE-2026-55985 published in NVD dataset

References

Related threats