CVE-2026-55985
Last modified
CVE-2026-55985 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Tycon Systems | TPDIN-Monitor-WEB2 | 2.3.9 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55985?
How severe is CVE-2026-55985?
How do I fix CVE-2026-55985?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55978An improper access control vulnerability in CatchPulse could…8.4
- CVE-2026-55979An improper access control check in CatchPulse's named pipe …5.2
- CVE-2026-5598Covert timing channel vulnerability in Legion of the Bouncy …7.5
- CVE-2026-55980A denial-of-service vulnerability in CatchPulse could allow …5.5
- CVE-2026-55982OIDC userinfo Endpoint Returns Identity Claims Without Enfor…9.1
- CVE-2026-55984Null Pointer Dereference in AddTime API Causes Authenticated…2.7
- CVE-2026-55986Email Management API Bypasses ManageCredentials Feature Rest…5.4
- CVE-2026-55987OAuth2 sign-in reactivates an administrator-deactivated acco…8.1
- CVE-2026-5599A user with API access and "manage users" permission in any …7.3
- CVE-2026-55990In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when…5.9
- CVE-2026-55991In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a r…5.9
- CVE-2026-55993Improper Input Validation, Exposure of Sensitive Information…7.5
Are you affected by CVE-2026-55985?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
