securityonline.info 7/24/2026, 4:31:49 PM · external

Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8

Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article discusses a critical vulnerability (CVE-2026-61884) in the Tycon TPDIN-Monitor-WEB2 power monitor, which allows attackers to bypass authentication due to lack of server-side credential validation, rated CVSS 9.8. This vulnerability can lead to unauthorized access and control over connected equipment, raising safety and operational risks. Additionally, another issue (CVE-2026-55985) involves exposed system credentials stored in cleartext, which can be exploited once access is gained.

As of now, there are no patches available, and the recommended mitigation includes isolating affected devices from public access and setting up firewalls. CISA has not reported any public exploitation of these vulnerabilities.

View full article

Article by CyberSIXT