Cross-Site Request Forgery Vulnerability in Tycon Systems TPDIN-Monitor-WEB3
CVE-2026-82712
8.6HIGH
What is CVE-2026-82712?
The TPDIN-Monitor-WEB3 from Tycon Systems versions 2.2.9 and earlier are susceptible to a cross-site request forgery (CSRF) attack. This type of vulnerability allows attackers to trick users into executing unintended actions on the device without their knowledge or consent. By exploiting this flaw, an attacker could potentially alter settings or make state-changing requests, compromising the security and integrity of the device.
Affected Version(s)
TPDIN-Monitor-WEB3 0 <= 2.2.9
TPDIN-Monitor-WEB3 v2.4.2
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdiwelli Guled reported this vulnerability to CISA.
