Description
A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateUserPassword of the component API Endpoint. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-05-25
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Tiandy Easy7 Integrated Management Platform 7.17.0 allows remote manipulation of the /rest/user/updateUserPassword endpoint, which results in weak password recovery. An attacker can trigger the endpoint to reset or bypass password policies, enabling unauthorized access to user accounts without needing to know current credentials. This flaw is classified as CWE‑640, which involves improper handling of password management. The impact is the potential compromise of confidentiality and integrity of protected data due to account takeover.

Affected Systems

The affected product is Tiandy Easy7 Integrated Management Platform version 7.17.0, used in network video recorders and security platforms that provide integrated management of camera devices. Only the /rest/user/updateUserPassword API endpoint is impacted, and no other components or versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity. Because the exploit is publicly disclosed, it can be conducted remotely and the vendor has not addressed the issue. The EPSS score is unavailable, but the lack of a vendor response and public disclosure suggest a realistic chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the remote nature and potential for account takeover make it a priority for remediation.

Generated by OpenCVE AI on May 25, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a version where the /rest/user/updateUserPassword endpoint is removed or hardened
  • Restrict network access to the REST API by placing it behind a firewall or VPN and enforcing strict authentication before allowing password reset operations
  • Implement additional authentication steps for password recovery, such as multi‑factor verification or security question validation, to mitigate misuse of the endpoint

Generated by OpenCVE AI on May 25, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 15:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateUserPassword of the component API Endpoint. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Tiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword password recovery
First Time appeared Tiandy
Tiandy easy7 Integrated Management Platform
Weaknesses CWE-640
CPEs cpe:2.3:a:tiandy:easy7_integrated_management_platform:*:*:*:*:*:*:*:*
Vendors & Products Tiandy
Tiandy easy7 Integrated Management Platform
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tiandy Easy7 Integrated Management Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-25T14:30:37.779Z

Reserved: 2026-05-24T08:55:40.195Z

Link: CVE-2026-9466

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T17:00:14Z

Weaknesses