Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8
ID: 7cd6fca4-cd7b-5d1b-aa0a-087f2d849259
STIX ID: report--7cd6fca4-cd7b-5d1b-aa0a-087f2d849259
Feed Name: securityonline.info
## TL;DR CISA published advisory ICSA-26-202-01 (July 21, 2026) describing a critical authentication bypass in the Tycon TPDIN-Monitor-WEB2 power monitor that allows remote attackers to obtain full administrative sessions and control onboard relays; a second issue exposes system credentials in cleartext. No vendor fix has been confirmed; CISA rates the bypass at CVSS 9.8 (3.1) and recommends immediate isolation from the public internet, firewalling, network segmentation, and VPNs for remote access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
