Impact
The vulnerability in Tiandy Easy7 Integrated Management Platform 7.17.0 allows remote manipulation of the /rest/user/updateUserPassword endpoint, which results in weak password recovery. An attacker can trigger the endpoint to reset or bypass password policies, enabling unauthorized access to user accounts without needing to know current credentials. This flaw is classified as CWE‑640, which involves improper handling of password management. The impact is the potential compromise of confidentiality and integrity of protected data due to account takeover.
Affected Systems
The affected product is Tiandy Easy7 Integrated Management Platform version 7.17.0, used in network video recorders and security platforms that provide integrated management of camera devices. Only the /rest/user/updateUserPassword API endpoint is impacted, and no other components or versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. Because the exploit is publicly disclosed, it can be conducted remotely and the vendor has not addressed the issue. The EPSS score is unavailable, but the lack of a vendor response and public disclosure suggest a realistic chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the remote nature and potential for account takeover make it a priority for remediation.
OpenCVE Enrichment