Executive brief
Tycon Systems TPDIN-Monitor-WEB3 is a web-based monitoring and management interface for power and environmental monitoring devices. The software contains hard-coded credentials that could allow an attacker with network access to log in and intercept sensitive device information, configuration data, or control settings without authentication.
Technical details
The vulnerability is a hard-coded credential use in TPDIN-Monitor-WEB3 versions 2.2.9 and prior. This allows an unauthenticated or low-privileged attacker with network access to the web interface to authenticate using embedded credentials and gain unauthorized administrative access. An attacker can exploit this via the network to intercept sensitive information, modify device configurations, or disrupt monitoring operations. Patches appear to be available in version 2.4.2 or later based on the firmware references.
Affected products
- Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior
Timeline
- 2026-09-04: disclosed