CVE-2026-61884
Received Received - Intake

Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass

Vulnerability report for CVE-2026-61884, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: ICS-CERT

Description

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-25
AI Q&A
2026-07-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tycon_systems tpdin-monitor-web2 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in Tycon Systems TPDIN-Monitor-WEB2 allows unauthenticated remote attackers to bypass login authentication by submitting empty credential fields. This grants full administrative access to the device, enabling control over power relays, device reboots, remote access services, and network settings.

Detection Guidance

To detect this vulnerability, check if the Tycon Systems TPDIN-Monitor-WEB2 web interface allows login with empty credentials. Test by submitting blank username and password fields in the login form. If access is granted, the system is vulnerable.

Impact Analysis

An attacker could exploit this to disrupt connected infrastructure or cause physical damage to equipment by manipulating power relays, rebooting devices, or altering network configurations. The high CVSS score indicates severe potential impact.

Compliance Impact

This vulnerability allows unauthenticated attackers to gain full administrative access to the device, potentially exposing sensitive data or disrupting critical operations. This could violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) by enabling unauthorized access to systems handling personal or protected health information.

Mitigation Strategies

Immediately update the Tycon Systems TPDIN-Monitor-WEB2 firmware to the latest version provided by the vendor. Disable remote access to the web interface if not required. Implement network segmentation to isolate the device from critical systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61884. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart