Back to overview

CVE-2026-55985

MEDIUM
4.3
CVSS 3.1
Description
The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.

Metadata

CVE ID
CVE-2026-55985
State
PUBLISHED
Assigner
icscert
Reserved
2026-07-13 18:17 UTC
Published
2026-07-24 21:37 UTC
Last updated
2026-07-24 21:37 UTC
Primary CWE
CWE-312
CWE-312
Vendor / Product
Tycon Systems / TPDIN-Monitor-WEB2
Sources
cve.org  ·  NVD

Severity & Metrics

4.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
Tycon Systems TPDIN-Monitor-WEB2 2.3.9
Weakness (CWE)
CWESourceDescription
CWE-312 cna CWE-312
CVSS scores (2)
ScoreSeverityVersionSourceVector
5.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
4.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Back to overview