Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.
Units already running v2.4.2, for subsequent updates (signed container):
https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw
All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX):
https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex
A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.
For more information, contact Tycon Systems:
https://www.tyconsystems.com/contact