THE article discusses a critical vulnerability (CVE-2026-61884) in the Tycon TPDIN-Monitor-WEB2 power monitor, which allows attackers to bypass authentication due to lack of server-side credential validation, rated CVSS 9.8. This vulnerability can lead to unauthorized access and control over connected equipment, raising safety and operational risks. Additionally, another issue (CVE-2026-55985) involves exposed system credentials stored in cleartext, which can be exploited once access is gained.
As of now, there are no patches available, and the recommended mitigation includes isolating affected devices from public access and setting up firewalls. CISA has not reported any public exploitation of these vulnerabilities.