news.mlab.sh
Back to the feed
vulnerability

Tycon Systems TPDIN-Monitor-WEB2

Critical
Summary

Tycon Systems TPDIN-Monitor-WEB2 versions 2.3.9 are vulnerable to a critical authentication bypass flaw, allowing unauthenticated remote attackers to gain full administrative access to the device. This could lead to disruption of connected infrastructure, physical damage to equipment, and potential credential compromise. Tycon Systems has not responded to CISA’s attempts at coordination, and users are urged to contact the vendor for updates.

Tycon Systems TPDIN-Monitor-WEB2 versions 2.3.9 are vulnerable to a critical security flaw. The web management interface of the device lacks proper server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment. The CISA has not received a response from Tycon Systems regarding coordination. Users are strongly encouraged to contact Tycon Systems for updates and patches. The device’s web management interface stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users, further increasing the risk of credential compromise and potential lateral movement within a network. CISA recommends minimizing network exposure for control system devices and isolating them from business networks, utilizing more secure remote access methods like VPNs (while acknowledging VPN vulnerabilities), and conducting thorough impact analysis and risk assessments.

Read the full article at CISA Advisories