PT-2026-24005 · Tiandy · Tiandy Video Surveillance System

Red88-Debug

+1

·

Published

2026-03-09

·

Updated

2026-03-10

·

CVE-2026-3797

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tiandy Video Surveillance System version 7.17.0
Description A security issue exists in Tiandy Video Surveillance System that allows for unrestricted file uploads. This is due to the manipulation of the fileName argument within the uploadFile function located in the /src/com/tiandy/easy7/core/rest/CLS REST File.java file. The attack can be initiated remotely. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-3797

Affected Products

Tiandy Video Surveillance System