CISA has published an advisory for Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, identifying three vulnerabilities: Use of Hard-coded Credentials (CVE-2026-77847), Cross-Site Request Forgery (CVE-2026-82712), and Missing Authorization (CVE-2026-82684). Successful exploitation could allow attackers to perform man-in-the-middle attacks, cause factory resets, wipe credentials, or retrieve sensitive information. The highest CVSS v3.1 score is 8.8 (HIGH) for the CSRF vulnerability. Affected devices are deployed worldwide in Critical Manufacturing and Energy sectors. Tycon Systems has released firmware v2.4.2 as a fix, with separate update artifacts for legacy (Intel HEX) and newer (signed .tfw container) units. The vulnerabilities were reported by Abdiwelli Guled to CISA. No known public exploitation has been reported at this time.