CVE-2026-4287: Tiandy Easy7 Integrated Management Platform Endpoint queryResources sql injection
A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/queryResources of the component Endpoint. Performing a manipulation of the argument areaId results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4287?
CVE-2026-4287 has been classified as a high severity vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2026-4287?
To mitigate CVE-2026-4287, update the Tiandy Easy7 Integrated Management Platform to the latest patched version.
What systems are affected by CVE-2026-4287?
CVE-2026-4287 affects the Tiandy Easy7 Integrated Management Platform specifically version 7.17.0.
What type of vulnerability is CVE-2026-4287?
CVE-2026-4287 is classified as an SQL injection vulnerability affecting the Endpoint component.
Can CVE-2026-4287 lead to data compromise?
Yes, if exploited, CVE-2026-4287 can lead to unauthorized access to the database and potential data compromise.