# Tycon TPDIN-Monitor-WEB2 auth bypass flaw

Published: 2026-07-21 · Severity: high · Sectors: manufacturing
Canonical: https://vorant.io/reports/193c1e3b-4f0d-534a-b4f6-867e6746606c/tycon-tpdin-monitor-web2-auth-bypass-flaw

> An unauthenticated authentication bypass and cleartext credential storage in Tycon Systems TPDIN-Monitor-WEB2 devices could let attackers gain admin access and disrupt physical infrastructure.

CISA published an ICS advisory for Tycon Systems TPDIN-Monitor-WEB2 version 2.3.9, detailing two vulnerabilities. CVE-2026-61884 is a critical authentication bypass (CWE-288) in which the web management interface fails to validate credentials server-side, allowing an unauthenticated remote attacker to submit empty login fields and obtain a full administrative session, including control over power relays, device reboot, remote access services, and network settings. CVE-2026-55985 is a cleartext credential storage issue (CWE-312) that exposes system credentials on a configuration page visible to any authenticated user, which could be leveraged to pivot to other network systems.

The affected product is deployed worldwide within the Critical Manufacturing sector, and the vendor, headquartered in the United States, did not respond to CISA's coordination attempts, leaving no vendor-supplied patch available. CISA recommends standard ICS defense-in-depth measures — network isolation, firewalling, and VPN use for remote access — since no fix currently exists. No public exploitation has been reported to date, but the combination of trivial authentication bypass and physical control capabilities (relay management, reboot) presents a genuine safety risk if exploited.

## Mentioned in this report

- Vulnerabilities: CVE-2026-55985, CVE-2026-61884

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/193c1e3b-4f0d-534a-b4f6-867e6746606c/tycon-tpdin-monitor-web2-auth-bypass-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
