Tycon Systems TPDIN-Monitor-WEB3

2026-09-03T19:23:18Z13662fcc948ae90fe1e676bf0b699e7a9620786a31fc1cea604efe9b4597312e
CVE-2025-10478CVE-2026-12663CVE-2026-19471CVE-2026-19472CVE-2026-75925CVE-2026-77393CVE-2026-77847CVE-2026-82684CVE-2026-82712CISA ICS advisoryCRLF injectionCSRFICSIXONInductive AutomationOT securityPyramid SolutionsRockwell AutomationSCADATycon Systemsarbitrary code executionbuffer overflowcritical infrastructuredenial of servicehard-coded credentialsindustrial control systemsmissing authorizationprivilege escalationremote code executionstored XSS

What happened

CISA ICS advisories dated September 3, 2026 cover vulnerabilities in Tycon Systems TPDIN-Monitor-WEB3, Pyramid Solutions NetStaX EtherNet/IP Stack, Inductive Automation Ignition, Rockwell Automation 1756-ENBT and ArmorStart LT products, Rockwell ControlFLASH, and the IXON VPN Client. Impacts include hard-coded credential exposure, MitM attacks, unauthorized project creation, stack-based buffer overflow, denial of service, stored XSS, arbitrary code execution, and privileged remote code execution across critical infrastructure environments. The highest reported severity is critical, including a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
13662fcc948ae90fe1e676bf0b699e7a9620786a31fc1cea604efe9b4597312e
Enrichment time
2026-09-03T19:23:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.