CVE-2026-55985
Received Received - Intake

Tycon Systems TPDIN-Monitor-WEB2 Cleartext Credential Storage

Vulnerability report for CVE-2026-55985, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: ICS-CERT

Description

The web management interface inΒ  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-25
AI Q&A
2026-07-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tycon_systems tpdin-monitor-web2 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in Tycon Systems TPDIN-Monitor-WEB2 allows authenticated users to view system credentials stored in cleartext on a configuration page in the web management interface. This means anyone with access to the administrative dashboard can read these credentials and potentially use them to compromise other systems on the local network.

Detection Guidance

Check the web management interface of Tycon Systems TPDIN-Monitor-WEB2 for a configuration page where credentials are displayed. Log in as an authenticated user and inspect the page for plaintext credentials. No specific commands are provided, but manual inspection of the interface is required.

Impact Analysis

If you use Tycon Systems TPDIN-Monitor-WEB2, an attacker with access to the administrative dashboard could steal stored credentials and gain unauthorized access to other systems on your network. This could lead to data breaches, unauthorized control of connected devices, or further network compromise.

Compliance Impact

This vulnerability could violate compliance requirements that mandate protection of sensitive data, such as GDPR (data confidentiality) and HIPAA (protected health information security). Storing credentials in cleartext and allowing unauthorized access may result in non-compliance, potential fines, and reputational damage.

Mitigation Strategies

Restrict access to the administrative dashboard to trusted users only. Update the firmware or software to a patched version if available. Consider disabling the affected configuration page until a fix is applied. Monitor network traffic for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55985. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart