CVE-2026-55985

MEDIUM

Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information

Title source: cna
STIX 2.1

Description

The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 4.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
Tycon Systems/TPDIN-Monitor-WEB2 2.3.9
Published Jul 24, 2026
Tracked Since Jul 25, 2026