# Tycon TPDIN-Monitor-WEB3 vulnerabilities patched

Published: 2026-09-03 · Severity: routine · Sectors: manufacturing, energy
Canonical: https://vorant.io/reports/044c7e28-5961-51a5-bc51-df9b3a619ee8/tycon-tpdin-monitor-web3-vulnerabilities-patched

> CISA advises three vulnerabilities in Tycon Systems TPDIN-Monitor-WEB3 firmware could let attackers steal credentials, force factory resets, or perform MitM attacks.

CISA published an ICS advisory covering three vulnerabilities in Tycon Systems TPDIN-Monitor-WEB3, a device monitoring product used in critical manufacturing and energy sectors worldwide. Affected versions are 2.2.9 and prior. The flaws include hard-coded credentials (CVE-2026-77847) that could allow interception of sensitive information, a cross-site request forgery weakness (CVE-2026-82712) enabling state-changing operations on the device, and a missing authorization issue (CVE-2026-82684) that could allow extraction of system credentials, configurations, or flash contents. Combined, these could enable man-in-the-middle attacks, forced factory resets, credential wiping, or sensitive data disclosure.

Tycon Systems has released Firmware v2.4.2 to remediate the issues, with separate update artifacts depending on whether units are already on v2.4.2 or still running legacy v2.2.9 (which requires a direct Intel HEX update path). CISA states no known public exploitation of these vulnerabilities has been reported at this time, and recommends standard ICS defensive practices such as network segmentation, firewalling control system networks, and using VPNs for remote access. The vulnerabilities were reported to CISA by researcher Abdiwelli Guled.

## Mentioned in this report

- Vulnerabilities: CVE-2026-77847, CVE-2026-82684, CVE-2026-82712

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/044c7e28-5961-51a5-bc51-df9b3a619ee8/tycon-tpdin-monitor-web3-vulnerabilities-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
