PatchSiren

Tycon Systems CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Tycon Systems CVE published 2026-07-24

CVE-2026-61884

The Tycon Systems TPDIN-Monitor-WEB2 web management interface does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, r [truncated]

MEDIUM Tycon Systems CVE published 2026-07-24

CVE-2026-55985

The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network. This vulnerability poses a significant risk as it allows unaut [truncated]