Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2. Units already running v2.4.2, for subsequent updates (signed container): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs. For more information, contact Tycon Systems: https://www.tyconsystems.com/contact
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device. | |
| Title | Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-04T20:58:57.898Z
Reserved: 2026-09-01T17:01:04.758Z
Link: CVE-2026-82712
No data.
Status : Received
Published: 2026-09-04T21:17:26.100
Modified: 2026-09-04T21:17:26.100
Link: CVE-2026-82712
No data.
OpenCVE Enrichment
No data.
-
CWE-352
Cross-Site Request Forgery (CSRF)