Security1 distinct publisher2 min readPublished
The advisory on TPDIN-Monitor-WEB3 2.2.9 and earlier lists hard-coded credentials, cross-site request forgery and missing authorization on units running in energy and critical manufacturing. Firmware v2.4.2 is the whole fix.
The Watch · Security desk

security
Thirteen CVEs land on the Ebyte NA111-M while the vendor stops answering CISA1 distinct publisher
security
Unconfigured Tycon TPDIN monitors hand full relay control to anyone on the network1 distinct publisher
security
Stored XSS in ArmorStart LT waits for the engineer who opens the device's web page1 distinct publisher
security
Xiiaozet's LK100W lets an unauthenticated caller switch on its admin services1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
The three weaknesses read as an order of operations. Missing authorization is the entry: CISA says it allows extraction of system credentials, configurations, or flash contents [5], and a missing-authorization defect, by construction, does not require the credential it gives up. The hard-coded credential is what makes recovered material durable [7], because a secret compiled into firmware cannot be rotated from a settings page, and the advisory lists no configuration change that removes it [13]. Cross-site request forgery supplies the write side, described as allowing an attacker to perform state changing operations on the device [6]. Factory reset and credential wipe show up in the summary as outcomes [2], though the document leaves both without a specific CVE number attached, and without mapping any of the three identifiers to one of the three weakness classes [15].
The remediation arithmetic is unusually clean for embedded gear at this end of the market. There are three CVEs [1], one fixed version [8], and one install step from 2.2.9 with no intermediate build [9]. One hands-on visit per unit clears all three [1]. That is the whole plan the advisory offers. Vendor fix, download links, the single-step note, a contact page [13].
Ranking this against the rest of the week's ICS traffic has to be done without numbers, because the metrics sections for all three CVEs are empty as published [12]. Exploitability is the better guide in any case. The missing authorization issue needs network reach to the device's web interface and nothing else, which makes it the one to price first. The CSRF needs an authenticated operator's browser to load attacker-controlled content, so its realistic path runs through an engineering workstation that can see both the device and the open internet. Neither requires the attacker to know anything about the site beyond the fact that a TPDIN unit answers.
Scope is worldwide, in critical manufacturing and energy, from a US-headquartered vendor [3][4]. What a forced reset actually costs depends on what the unit reports to and what depends on that reporting, and the advisory does not say. It credits one researcher, Abdiwelli Guled, for the report [11], and its vulnerability and remediation sections don't name exploit code, a threat actor, or a campaign [14]. The bugs are confirmed and the fix has shipped, with no public tooling attached to them yet [/]. The work is inventory and a flashing schedule, not incident response.
Ranked by verification strength, evidence, and original report placement.
The advisory's remediation entries for each vulnerability consist of the vendor firmware fix, two firmware download links, the note that a v2.2.9 unit reaches v2.4.2 in one step, and a vendor contact link; no configuration change or compensating control is listed.
CISA's advisory states that Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are affected, under CVE-2026-77847, CVE-2026-82712 and CVE-2026-82684.
CISA states successful exploitation could allow an attacker to perform a man-in-the-middle attack, cause a factory reset, wipe credentials, or retrieve sensitive information.
The advisory lists the affected critical infrastructure sectors as Critical Manufacturing and Energy, and the countries/areas deployed as worldwide.
The advisory lists Tycon Systems' company headquarters location as the United States.
TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability (CWE-862) that could allow an attacker to extract system credentials, configurations, or flash contents.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Issuer of record, unscored
Everything load-carrying in this story — the version ceiling, three weakness classes, two firmware artifacts, the reporter's name — comes straight from CISA, which is the authority that publishes these findings rather than someone relaying them. That is clean sourcing, and it is also the ceiling: nothing has been independently reproduced, the metrics sections are empty, and the three CVE identifiers sit in a group with no indication of which flaw is which.
Footprint stated, uptake unknown
CISA says these monitors run worldwide in energy and critical manufacturing, which describes where the risk sits, not how much of it has been retired. No one has published how many TPDIN units are installed, how many still run 2.2.9, or whether a single site has flashed v2.4.2 since the files went up. Turning 'worldwide' into a number would be invention, so we leave this open.
Reads flatter than it lands
The alarming phrases in this story — credentials wiped, a factory reset triggered remotely — are CISA's own words, not an escalation of them. If anything the account sits slightly under its facts: three separate weakness classes on devices sitting in substations and plant rooms arrive with no severity number attached and no exploitation claim to dramatise, so a reader skimming for urgency finds none, while the actual remediation is a physical flash of every unit.
Nobody selling, vendor self-reporting
The publisher has no product in the frame: CISA earns nothing from an advisory, and Tycon's appearance in it is as the party that shipped a fix. The soft spot is narrow but real — the entire remediation section is the vendor's account of its own firmware, two links plus an assurance that one install gets a 2.2.9 unit to 2.4.2, unverified by anyone else — and the finder collects the reputational credit that reported findings normally carry.
Right source, only source
One publisher, and it happens to be the correct one, which is why this does not sit lower. We are confident about what the advisory says and much less confident about what it withholds: no severity scoring, no identifier-to-weakness mapping, no exposure estimate, and silence on exploitation. A vendor bulletin or a second researcher account would settle most of that.