Security1 distinct publisher2 min readPublished
CISA's advisory on the Tycon TPDIN-Monitor-WEB2 covers two flaws below firmware 2.4.5, and the first needs no exploit at all, only a unit whose installer never set the password the vendor expected.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
CVE-2026-55985 is written as a post-authentication problem. On an unconfigured unit running 2.4.4 there is nothing to authenticate against, so the page that prints system credentials in cleartext sits behind no gate [13]. The prerequisite for both issues is the same, and it is a route to the web interface [3][4].
The reset behavior is the detail worth writing down. Tycon's guidance for units still on 2.4.4 or earlier is to set an administrator username and strong password on the Network Configuration page, confirm in a private browser window that a login is demanded, and repeat that after any factory reset [7]. That last instruction is the tell. Under 2.4.4 a reset restores the shipped blank state; under 2.4.5 the interface is not served until credentials exist, so a reset leaves the unit closed [16].
Count the remediation work. The advisory carries four vendor mitigations. Firmware 2.4.5 supersedes exactly one, the manual password step, leaving three that still apply after the upgrade [15]. Two of those three are credential rotation: the factory-default SNMP community strings and the Telnet password, if they were left at shipped values [8], and moving device alerts to a dedicated mail account rather than one also used for other sensitive purposes [9]. Stripping cleartext credentials from the response does not retract what an open unit already displayed to whoever loaded that page [14].
The third surviving mitigation is placement. The interface is HTTP only, and Tycon says keep the unit on a private network behind a firewall or VPN [10]. That was true the day the device shipped.
CISA lists the product under Critical Manufacturing and deployed worldwide, with the vendor headquartered in the United States [11]. Its summary of impact runs to accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, with a physical safety risk attached [17]. Read that against the access requirement, which is a browser and a reachable address. Abdiwelli Guled reported both issues to CISA [12].
The pattern here is familiar from installer-configured industrial gear generally: the vulnerability is the shipped state, and the population at risk is whatever fraction of units went into service and never got a first-use password [3]. Firmware 2.4.5 is the fix because it removes the option of skipping that step [6].
Ranked by verification strength, evidence, and original report placement.
An attacker with network access to an unconfigured unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.
CISA's summary states that successful exploitation could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.
CISA published an ICS advisory, ICSA-26-202-01, covering Tycon Systems TPDIN-Monitor-WEB2 (Update A).
Affected versions are Tycon Systems TPDIN-Monitor-WEB2 below firmware 2.4.5, tracked as CVE-2026-61884 and CVE-2026-55985.
The device ships without HTTP credentials configured, intended for an installer to set them on first use; on firmware 2.4.4 and earlier a unit left in that unconfigured state serves the web management interface without requiring any login. CISA maps this to CWE-306, Missing Authentication for Critical Function.
The web management interface stores and displays system credentials in cleartext on a configuration page accessible to authenticated users; any party with access to the administrative dashboard can immediately read those credentials, which may be used to compromise other systems on the local network. CISA maps this to CWE-312, Cleartext Storage of Sensitive Information.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CISA's Ebyte advisory carries no fixed version, because the vendor stopped answering1 distinct publisher
security
Rockwell's ControlFLASH installer gave the Everyone group write access to its own program folder1 distinct publisher
security
A CRLF injection in IXON's VPN client gives unauthenticated callers root that survives reboot1 distinct publisher
security
Thirteen CVEs land on the Ebyte NA111-M while the vendor stops answering CISA1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Issuer-grade detail, nobody's second look
CISA gives the specifics that make a defect actionable: a firmware cutoff, two CVE numbers, CWE mappings, the exact controls an intruder reaches, and a named researcher. What it withholds is corroboration and calibration — the metrics sections carry no score, and the only technical account of the device is this one page, with the vendor's remediation text quoted inside it.
Fix shipped, fleet unknown
The one hard adoption fact is that 2.4.5 exists and does what the advisory says. Everything on the other side of the ledger is blank: no count of installed units, nothing on how many still sit unconfigured, no scan data on internet-reachable dashboards, and no reported exploitation. 'Worldwide' and 'Critical Manufacturing' are categories, not measurements.
Roughly in the advisory's own register
Physical relay control with no login is dramatic on its own terms, and CISA does not oversell it — the physical-safety wording sits next to an explicit note that no exploitation has been reported. Our headline keeps the condition that matters in front: unconfigured units, legacy firmware. The small remaining inflation is structural rather than rhetorical, since neither the number of exposed units nor a severity score exists to size any of it.
Agency page, vendor voice
CISA has no product to sell and a mandate to publish, which keeps distortion low. The pressure is one layer down: every remediation and mitigation sentence is Tycon's, and the vendor's framing — the device is 'intended for an installer to set them on first use' — quietly locates the fault in deployment practice rather than in a factory default that serves a control interface to anyone. The patch, which now refuses to run unconfigured, concedes the other reading.
Firm on the defect, blind on scale
Confidence splits cleanly. What the flaws are, which firmware carries them and what closes them can be trusted at close to face value, coming from the coordinating agency with the vendor on record. How much of the world is actually exposed is unknowable from this reporting, and the Update A label with no accompanying revision note is a reminder that even the document's own history is partly undisclosed.