Impact
The vulnerability exists in the Tiandy Easy7 Integrated Management Platform (version 7.17.0) in an undocumented function of the endpoint /rest/devStatus/getDevDetailedInfo. Manipulating the ID argument allows an attacker to inject arbitrary SQL statements. The injected input can lead to unauthorized data disclosure, modification, or deletion, compromising both confidentiality and integrity of the system database.
Affected Systems
The affected system is Tiandy Easy7 Integrated Management Platform, specifically version 7.17.0 as identified by the vendor.
Risk and Exploitability
The CVSS Base score is 6.9, indicating a moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Exploit code is publicly available, and the attack can be performed remotely by sending a crafted request to the vulnerable endpoint. The lack of vendor response further elevates the risk, meaning any unpatched installations remain vulnerable and could be targeted by attackers.
OpenCVE Enrichment