Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.
The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected:
TPDIN-Monitor-WEB2 2.3.9
Vendor
Equipment
Tycon Systems
Tycon Systems TPDIN-Monitor-WEB2
Authentication Bypass Using an Alternate Path or Channel, Cleartext Storage of Sensitive Information
The web management interface of the affected device does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check...