What is CVE-2026-61884?
This vulnerability exists in the web management interface of Tycon Systems TPDIN-Monitor-WEB2 due to lack of server-side validation of credentials during login. A remote unauthenticated attacker can gain admin access by submitting empty values for both credential fields. Firmware update is recommended.
Azərbaycanca: Bu boşluq Tycon Systems TPDIN-Monitor-WEB2 cihazının web idarəetmə interfeysində autentifikasiyanın server tərəfində düzgün yoxlanılmaması ilə bağlıdır. Uzaqdan hücum edən şəxs giriş sahələrini boş buraxaraq admin səlahiyyətləri əldə edə bilər. Cihazın proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
How can an attacker gain admin access on the Tycon Systems TPDIN-Monitor-WEB2 device using CVE-2026-61884?
An attacker can gain admin access by submitting empty values for both credential fields in the web management interface, bypassing the server-side authentication check.
What is the recommended mitigation for CVE-2026-61884?
The vendor recommends applying a firmware update to the affected device.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.