Skip to main content

CVE detail

CVE-2026-55985

The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.

CVSS 5.3 · MediumBuzz score 28.9

Buzz score

Why this CVE is surfacing

Buzz score total 28.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 13.9 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
13.9
3 evidence mentions in the snapshot
Diversity score
15.0
3 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
3
within the 30d window
Peak daily
2
highest bucket

Evidence

Source links by recency

Newest mentions first
3 source links · newest first
  • https://www.tyconsystems.com/contactwww.tyconsystems.com

    No excerpt available.

    referencewww.tyconsystems.comJul 24, 2026, 10:16 PM
  • No excerpt available.

    Exploitgithub.comJul 24, 2026, 10:16 PM
  • Tycon Systems TPDIN-Monitor-WEB2CISA Alerts

    facturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-61884 The web management interface of the affected device does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attac

    governmentwww.cisa.govJul 21, 2026, 12:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-16802

    Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read s…

    CVSS 6.5 · Medium
    1 mention
  • CVE-2024-58023

    Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

    CVSS 8.4 · High
    1 mention
  • CVE-2026-65599

    n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mista…

    CVSS 5.1 · Medium
    2 mentions
  • CVE-2026-13380

    VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these resp…

    CVSS 9.0 · Critical
    2 mentions
  • CVE-2026-16213

    A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_p…

    CVSS 4.8 · Medium
    6 mentions
  • CVE-2026-55885

    Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, i…

    CVSS 6.8 · Medium
    2 mentions