Junglewise Threat Intelligence

CVE-2026-82712: Tycon Systems TPDIN-Monitor-WEB3 CSRF vulnerability

CVE-2026-82712 · Severity: high · CVSS 8.8 · Published 2026-09-04

Executive brief

The TPDIN-Monitor-WEB3 is a network monitoring and management appliance used to oversee industrial and IoT systems. A cross-site request forgery (CSRF) vulnerability in versions 2.2.9 and prior allows an attacker to trick an authenticated administrator into unwittingly performing unauthorized configuration changes or administrative actions on the device, potentially disrupting network monitoring, altering device settings, or disabling security controls.

Technical details

The vulnerability is a classic cross-site request forgery (CSRF) flaw in which the device's web interface fails to properly validate the origin and authenticity of state-changing requests. An attacker can craft a malicious web page or email containing a hidden request (e.g., via img tag, form submission, or JavaScript) that, when visited by an authenticated administrator, will execute unintended operations on the TPDIN-Monitor-WEB3 device. Exploitation requires an authenticated user to be tricked into visiting the attacker-controlled page while maintaining an active session with the device. The attacker can achieve unauthorized administrative actions such as modifying configuration, disabling features, or altering monitoring rules. The vulnerability affects versions 2.2.9 and prior; patches are available in version 2.4.2 and later.

Affected products

  • Tycon Systems TPDIN-Monitor-WEB3 2.2.9 and prior

Timeline

  • 2026-09-04: disclosed

References

Related threats