What is CVE-2026-55985?
CVE-2026-55985 is a vulnerability in the web management interface of Tycon Systems TPDIN-Monitor-WEB2, where system credentials are stored and displayed in cleartext on a configuration page accessible to authenticated users. Anyone with administrative dashboard access can immediately read these credentials, so restricting access and applying firmware updates is recommended.
Azərbaycanca: CVE-2026-55985 — Tycon Systems TPDIN-Monitor-WEB2 cihazının web idarəetmə interfeysində aşkarlanmış boşluqdur. Autentifikasiya olunmuş istifadəçilər üçün əlçatan olan konfiqurasiya səhifəsində sistem etimadnamələri (credentials) cleartext şəklində saxlanır və göstərilir. Hər hansı admin panelə girişi olan şəxs bu etimadnamələri dərhal oxuya bilər, ona görə də cihaza girişi məhdudlaşdırmaq və proqram təminatı yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What risk does CVE-2026-55985 pose to TPDIN-Monitor-WEB2 users?
Because system credentials are stored and displayed in cleartext on a configuration page accessible to authenticated users, anyone with access to the admin dashboard can immediately read this information.
How can I protect against CVE-2026-55985?
It is recommended to restrict access to the device and apply firmware updates.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.