THREAT OPS › Threat News › [NVD] CVE-2026-61884 (CRITICAL 9.8) — The Tycon Systems TPDIN-Monitor-WEB2
ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker w
[NVD] CVE-2026-61884 (CRITICAL 9.8) — The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker w
CVE-2026-61884 CVSS: 9.8 CRITICAL Published: 2026-07-24T22:16:50.963
The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full d
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-61884cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-61884