13 September 2026

A power monitor's fix ships as two files, and the units in the field accept only one.

CISA, the United States agency that publishes advisories on industrial equipment, has flagged three faults at once in a small power monitoring unit, the kind that sits at a site nobody visits and reports back over the network.

Brief card: A power monitor's fix ships as two files, and the units in the field accept only one.

CISA, the United States agency that publishes advisories on industrial equipment, has flagged three faults at once in a small power monitoring unit, the kind that sits at a site nobody visits and reports back over the network. The agency says an attacker could use them to pull credentials and configuration off the device, sit in the middle of its conversations, or reset it to factory settings and wipe what was stored on it.

The maker has released corrected firmware. The awkward part is in the remediation notes. The fix is published as two different files, and the units already installed can read only one of them: the newer signed package is unreadable to the older updater, and the older-format build is the one every deployed unit needs. A team that downloads the obvious file will watch the update fail.

The agency records the equipment as deployed worldwide and tags the advisory to manufacturing and energy. If your organisation runs outlying plant, pump stations, telecoms huts, solar and battery installations or a mine's remote reticulation, the person who needs this is whoever schedules firmware on the small boxes that rarely make it onto an asset register.

What a blank unit costs

A factory reset is not a crash, and that is what makes it expensive. The unit comes back. It comes back empty, without the addresses, thresholds and credentials that made it worth installing. On a site with people on it, that is an afternoon. On a borehole four hours down a district road, it is a vehicle, a driver, a technician and an unplanned call-out charged against a maintenance budget that had other plans for the month.

The quieter consequence is the credentials. The agency says the missing-authorisation fault could let an attacker extract stored credentials, configuration and the contents of the device's memory. Small monitoring units are rarely given their own passwords. They tend to inherit whatever the integrator was using across the site during commissioning, which is why a device that controls nothing much can still be worth someone's time.

The three faults do not sit at the same distance from an attacker. The credential defect is the least severe on the agency's own rating, and the published details put the attacker on the same local network as the device. The other two are reachable over the network, with one of them depending on an administrator being induced to act while logged in. For a site where the monitoring unit shares a network with contractor laptops and a shared remote-access account, that distinction narrows quickly.

The questions worth asking

The question to put to whoever holds the maintenance record is which of the two files applies to the units actually on site, and whether the person doing the update knows there is a choice to make. The vendor's notes say a legacy unit reaches the corrected build in one step, with no staged upgrade in between. That is good news, and it is buried where a busy technician will not see it.

The second question is for the integrator: who is responsible for firmware on devices at this tier, and when were they last touched? Monitoring hardware is frequently outside the contract that covers the controllers and the drives, which is how a unit ends up years behind without anyone being at fault.

The third is a scoping question rather than a security one. Which networks can reach the unit's management page today, and which accounts on those networks were issued to people who have since left? An operator who cannot answer that cannot size this, whatever the advisory says.

The fix exists and it is a single step. Whether it lands depends on a detail in the remediation notes that reads like housekeeping: a site that pulls the signed package, sees it rejected and concludes the update is broken has not failed at security, it has picked the wrong file. That is a five-minute discovery at a desk, or a wasted trip to a site four hours away.

The technical record

  • Advisory ICSA-26-246-08, released 3 September 2026. Affected: Tycon Systems TPDIN-Monitor-WEB3, versions 2.2.9 and prior.
  • CVE-2026-77847, use of hard-coded credentials (CWE-798). CVSS v3.1 6.5, CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. CVSS v4.0 7.1. Attack vector adjacent network.
  • CVE-2026-82712, cross-site request forgery (CWE-352). CVSS v3.1 8.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. CVSS v4.0 8.6. Requires a user to act.
  • CVE-2026-82684, missing authorization (CWE-862). CVSS v3.1 8.1, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N. CVSS v4.0 8.6. Requires some existing access.
  • Stated impact across the set: man-in-the-middle, an attacker interposing on traffic, plus factory reset, credential wipe and retrieval of sensitive information.
  • Remediation: firmware v2.4.2. Signed container TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw applies only to units already on v2.4.2. Legacy Intel HEX build TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex, a plain-text firmware format, covers all fielded units including v2.2.9 and installs in one step. A v2.2.9 updater accepts Intel HEX only and cannot read the signed container.
  • Deployment worldwide; sectors tagged as critical manufacturing and energy; vendor headquartered in the United States.
  • No public exploitation targeting these faults had been reported to the agency at publication. The advisory closes with the agency's usual segmentation and remote-access guidance.

Source

  • cisa.gov/news-events/ics-advisories/icsa-26-246-08

All intelligenceEditorial policy