CVE-2026-4187: Tiandy Easy7 Integrated Management Platform Device Identifier UpdateLocalDevInfo.jsp missing authentication
A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateLocalDevInfo.jsp of the component Device Identifier Handler. Such manipulation of the argument username/password leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4187?
CVE-2026-4187 is considered to have a critical severity due to missing authentication in a key function of the Tiandy Easy7 Integrated Management Platform.
How do I fix CVE-2026-4187?
To mitigate CVE-2026-4187, apply the latest security updates provided by Tiandy for the Easy7 Integrated Management Platform.
What versions are affected by CVE-2026-4187?
CVE-2026-4187 affects Tiandy Easy7 Integrated Management Platform version 7.17.0.
What is the impact of CVE-2026-4187?
The impact of CVE-2026-4187 can lead to unauthorized access to sensitive functions within the Tiandy Easy7 Integrated Management Platform.
Is CVE-2026-4187 exploitable remotely?
Yes, CVE-2026-4187 can be exploited remotely due to the lack of authentication in the vulnerable component.