PT-2026-25620 · Tiandy · Easy7 Integrated Management Platform

0Menc

+1

·

Publicado

2026-03-16

·

Atualizado

2026-03-16

·

CVE-2026-4221

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tiandy Easy7 Integrated Management Platform version 7.17.0
Description A flaw exists within the Tiandy Easy7 Integrated Management Platform that allows for unrestricted file uploads. This issue affects the /rest/file/uploadLedImage endpoint of the Endpoint component. The File parameter can be manipulated to achieve this unrestricted upload, and the attack can be initiated remotely. The exploit for this issue has been publicly released.
Recommendations Tiandy Easy7 Integrated Management Platform version 7.17.0: Address the unrestricted upload issue in the /rest/file/uploadLedImage endpoint by validating the File parameter.

Exploit

Correção

Unrestricted File Upload

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4221

Produtos afetados

Easy7 Integrated Management Platform