Executive brief
The Tycon Systems TPDIN-Monitor-WEB2, a device used to monitor and control power systems in industrial environments, contains a critical security flaw in its web management interface. An attacker can bypass the login screen entirely by simply leaving the username and password fields blank, gaining full administrative control over the device. This allows unauthorized individuals to shut down power relays, reboot equipment, or change network settings, potentially leading to significant operational disruptions or physical damage to connected infrastructure.
Technical details
A critical authentication bypass vulnerability (CWE-288) exists in the Tycon Systems TPDIN-Monitor-WEB2 web management interface due to a lack of server-side credential validation. An unauthenticated remote attacker can establish a valid administrative session by submitting empty strings for both the username and password fields during the login process. Once authenticated, the attacker gains unrestricted access to the device's management dashboard, enabling them to manipulate power relay states, trigger device reboots, modify remote access configurations, and alter network settings. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is available; users are advised to isolate these devices from the internet and use VPNs for remote access.
Affected products
- Tycon Systems TPDIN-Monitor-WEB2 2.3.9
Timeline
- 2026-07-21: advisory: Initial publication by CISA (ICSA-26-202-01)
- 2026-07-24: disclosed: NVD publication date