Vulnerability intelligence
CVE-2026-55985
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
CVSS Score
4.3
Medium
EPSS — Exploit Probability
0.1%
Riskier than 4% of all CVEs · checked 2026-09-05
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jul 24, 2026 · latest Jul 24, 2026
Coverage timeline
-
Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8securityonline.info · Jul 24, 2026