CVE-2026-9466
Received Received - Intake
Weak Password Recovery in Tiandy Easy7 Platform

Publication date: 2026-05-25

Last updated on: 2026-05-25

Assigner: VulDB

Description
A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateUserPassword of the component API Endpoint. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-25
Last Modified
2026-05-25
Generated
2026-05-26
AI Q&A
2026-05-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
tiandy easy7_integrated_management_platform 7.17.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Tiandy Easy7 Integrated Management Platform version 7.17.0, specifically in the API endpoint that processes the file /rest/user/updateUserPassword. The issue allows an attacker to manipulate the password recovery process, resulting in weak password recovery mechanisms. This vulnerability can be exploited remotely.


How can this vulnerability impact me? :

The vulnerability can lead to weak password recovery, which may allow unauthorized attackers to reset or recover user passwords without proper authorization. This could result in unauthorized access to user accounts or systems managed by the Tiandy Easy7 platform.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart