TL;DR
CISA published advisory ICSA-26-202-01 on July 21, 2026. It covers a critical Tycon authentication bypass in the TPDIN-Monitor-WEB2 power monitor. Tycon Systems never replied to CISA, so no vendor fix exists.
Why it matters
The TPDIN-Monitor-WEB2 is not an ordinary web app. It tracks voltages, currents, and temperatures at remote sites. It also switches power to attached equipment through four onboard relays. So a hijacked unit becomes a remote power switch.
CISA warns that abuse could disrupt connected infrastructure or damage equipment. The agency also flags a physical safety risk. These units often sit at tower sites and other unstaffed locations. That makes internet exposure a real concern.
How the attacks work
CVE-2026-61884: the critical bypass
The web interface never validates credentials on the server side. As a result, a remote attacker can defeat the login without any account. Success grants a full administrative session. From there, an attacker controls power relays, reboots, remote access settings, and network config. CISA scores it 9.8 under CVSS 3.1 and 9.3 under CVSS 4.0.
CVE-2026-55985: exposed credentials
The second flaw stores system credentials in cleartext. Any authenticated user can read them on a configuration page. Those credentials may then unlock other systems on the local network. It rates a milder 4.3 under CVSS 3.1 and 5.3 under CVSS 4.0. Chained after the bypass, however, it becomes a stepping stone.
Affected versions
CISA lists TPDIN-Monitor-WEB2 version 2.3.9 as affected. No fixed release has been confirmed.
Mitigation steps
Since no patch exists, isolation is the priority. First, take these devices off the public internet immediately. Next, place them behind firewalls and separate them from business networks. Use a VPN if remote access is truly required. Also check Tycon’s site for firmware newer than 2.3.9, though no fix is confirmed. CISA reports no known public exploitation of these flaws so far. Even so, this Tycon authentication bypass warrants action today.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.