Impact
A vulnerability in the YunaiV yudao‑cloud 2026.03 Admin API endpoint /admin-api/iot/data-sink/create exposes a Server‑Side Request Forgery flaw. By manipulating the IotDataSinkHttpConfig request, an attacker can trigger the server to issue outbound requests to arbitrary URLs, potentially accessing internal services or exfiltrating data. The flaw is triggered remotely, making it potentially exploitable from the internet and could lead to data disclosure or exploitation of internal resources.
Affected Systems
The affected product is YunaiV yudao‑cloud, version 2026.03. No other vendor or product versions are mentioned in the advisory.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation likelihood is unknown. However, because the flaw can be triggered remotely and the public has disclosed an exploit, the risk to networks that expose the vulnerable endpoint remains significant. Until a vendor patch is released, the principal mitigation is to restrict or monitor outbound traffic from this endpoint. The lack of vendor response increases the urgency to apply compensating controls.
OpenCVE Enrichment