A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateUserPassword of the component API Endpoint. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 28 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 15:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateUserPassword of the component API Endpoint. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Tiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword password recovery
First Time appeared Tiandy
Tiandy easy7 Integrated Management Platform
Weaknesses CWE-640
CPEs cpe:2.3:a:tiandy:easy7_integrated_management_platform:*:*:*:*:*:*:*:*
Vendors & Products Tiandy
Tiandy easy7 Integrated Management Platform
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-05-25T14:30:37.779Z

Updated: 2026-05-28T12:51:36.527Z

Reserved: 2026-05-24T08:55:40.195Z

Link: CVE-2026-9466

cve-icon Vulnrichment

Updated: 2026-05-28T12:51:32.885Z

cve-icon NVD

Status : Deferred

Published: 2026-05-25T16:16:20.507

Modified: 2026-05-26T19:54:40.357

Link: CVE-2026-9466

cve-icon Redhat

No data.