Update to firmware version 2.4.5 released by Tycon Systems. Set an administrator username and strong password on the Network Configuration page. Avoid exposing the web interface to the Internet; keep the unit on a private network behind a firewall or VPN. Change any factory-default SNMP community strings and Telnet passwords if left at shipped values. Leave Telnet disabled unless required.
Quick answers
What is CVE-2026-55985?
Update to firmware version 2.4.5 released by Tycon Systems. Set an administrator username and strong password on the Network Configuration page. Avoid exposing the web interface to the Internet; keep the unit on a private network behind a firewall or VPN. Change any factory-default SNMP community strings and Telnet passwords if left at shipped values. Leave Telnet disabled unless required.
How severe is CVE-2026-55985?
critical, CVSS 9.8
Is CVE-2026-55985 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-55985 be mitigated?
Update to firmware version 2.4.5 released by Tycon Systems. Set an administrator username and strong password on the Network Configuration page. Avoid exposing the web interface to the Internet; keep the unit on a private network behind a firewall or VPN. Change any factory-default SNMP community strings and Telnet passwords if left at shipped values. Leave Telnet disabled unless required.
CVSS
9.8
Vendor
Tycon Systems
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Tycon Systems TPDIN-Monitor-WEB2 (Update A)
Mitigation
Update to firmware version 2.4.5 released by Tycon Systems. Set an administrator username and strong password on the Network Configuration page. Avoid exposing the web interface to the Internet; keep the unit on a private network behind a firewall or VPN. Change any factory-default SNMP community strings and Telnet passwords if left at shipped values. Leave Telnet disabled unless required.
CISA and researcher Abdiwelli Guled have disclosed two vulnerabilities in Tycon Systems TPDIN-Monitor-WEB2 (Update A) firmware versions prior to 2.4.5. CVE-2026-61884 allows unauthenticated full device control due to missing authentication on the web management interface. CVE-2026-55985 permits authenticated users to view system credentials stored in cleartext. Both vulnerabilities affect firmware <2.4.5 and have been resolved in the latest release.