CVE-2026-4221
HIGHTiandy Easy7 Integrated Management Platform Endpoint uploadLedImage unrestricted upload
Title source: cnaDescription
A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage of the component Endpoint. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
References (4)
Core 4
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-351145 | Tiandy Easy7 Integrated Management Platform Endpoint uploadLedImage unrestricted upload
https://vuldb.com/?id.351145
Signature, Permissions Required signature
permissions-required
VDB-351145 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/?ctiid.351145
Third Party Advisory third-party-advisory
Submit #770534 | Tiandy Technologies Co., Ltd. Easy7 Integrated Management Platform 7.17.0 Unrestricted Upload of File with Dangerous Type
https://vuldb.com/?submit.770534
Scores
CVSS v3
7.3
EPSS
0.0028
EPSS Percentile
19.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-284
CWE-434
Status
published
Products (1)
Tiandy/Easy7 Integrated Management Platform
7.17.0
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026