Update to TPDIN-Monitor-WEB3 Firmware v2.4.2. Units on v2.2.9 should apply the Intel HEX update: https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex. Units already on v2.4.2 may use the signed container: https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw. Contact Tycon Systems for additional support.
Quick answers
What is CVE-2026-82684?
Update to TPDIN-Monitor-WEB3 Firmware v2.4.2. Units on v2.2.9 should apply the Intel HEX update: https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex. Units already on v2.4.2 may use the signed container: https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw. Contact Tycon Systems for additional support.
How severe is CVE-2026-82684?
high, CVSS 8.8
Is CVE-2026-82684 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-82684 be mitigated?
Update to TPDIN-Monitor-WEB3 Firmware v2.4.2. Units on v2.2.9 should apply the Intel HEX update: https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex. Units already on v2.4.2 may use the signed container: https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw. Contact Tycon Systems for additional support.
CVSS
8.8
Vendor
Tycon Systems
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
TPDIN-Monitor-WEB3
Mitigation
Update to TPDIN-Monitor-WEB3 Firmware v2.4.2. Units on v2.2.9 should apply the Intel HEX update: https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex. Units already on v2.4.2 may use the signed container: https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw. Contact Tycon Systems for additional support.
CISA has issued an industrial control systems advisory (ICSA-26-246-08) detailing three vulnerabilities in Tycon Systems TPDIN-Monitor-WEB3 firmware versions 2.2.9 and prior. The flaws involve use of hard-coded credentials (CVE-2026-77847), cross-site request forgery (CVE-2026-82712), and missing authorization (CVE-2026-82684). Successful exploitation could allow man-in-the-middle attacks, factory resets, credential wiping, sensitive information retrieval, and unauthorized state-changing operations. Tycon Systems has released firmware version 2.4.2 as a remediation, with specific update instructions for legacy units.