ics-otregulatorNewsThe Broadside1 min read

CISA flags Tycon TPDIN-Monitor-WEB2 authentication bypass

Tycon's nonresponse leaves network isolation carrying risk that a vendor patch should be reducing for critical manufacturing operators.


TL;DR

The Cybersecurity and Infrastructure Security Agency (CISA) disclosed two flaws in Tycon Systems TPDIN-Monitor-WEB2 2.3.9: CVE-2026-61884, a CVSS v3.1 9.8 authentication bypass using empty login fields, and CVE-2026-55985, a cleartext credential storage flaw scored CVSS v3.1 4.3. The product is deployed worldwide in critical manufacturing. Defense industrial base contractors and Cybersecurity Maturity Model Certification Third-Party Assessment Organizations (C3PAOs) should treat the web interface as immediate operational technology risk, because Tycon did not respond to CISA coordination and no vendor fix is listed.

CISA's ICSA-26-202-01 is a short advisory with a bad operational shape. Tycon Systems TPDIN-Monitor-WEB2 2.3.9 has a web management interface that, according to CISA, fails to validate credentials server-side. Submitting empty values for both credential fields establishes a valid administrative session. That is CVE-2026-61884, CVSS v3.1 9.8, against critical manufacturing deployments worldwide. The admin session reaches power relay management, device reboot, remote access service configuration and network settings, which is why this is a safety problem as well as a login bug.

The second issue, CVE-2026-55985, scores lower at CVSS v3.1 4.3 but pairs badly with the bypass. The web management interface stores and displays system credentials in cleartext on a configuration page accessible to authenticated users. CISA says those credentials may be used to compromise other systems on the local network. In an operational technology environment, that is a lateral movement path sitting behind the same dashboard the first bug can open.

The coordination note is the part practitioners cannot patch around with paperwork. Abdiwelli Guled reported the vulnerabilities to CISA, and Tycon did not respond to CISA's attempts at coordination. The agency lists no patched version, tells users to contact Tycon and keep systems up to date, and reports no known public exploitation specifically targeting these vulnerabilities. That leaves the basic question CISA cannot answer for asset owners: when, or whether, a patched build appears.

For defense industrial base contractors and Cybersecurity Maturity Model Certification Third-Party Assessment Organizations (C3PAOs), the Monday work is inventory and exposure reduction: find TPDIN-Monitor-WEB2 2.3.9, remove internet access, put control system networks behind firewalls, isolate them from business networks, and make any remote access depend on updated virtual private network infrastructure. Until Tycon ships a patch, those compensating controls are the fix.


Published ·Deep Fathom