CVE-2026-9466
Weak Password Recovery in Tiandy Easy7 Platform
Publication date: 2026-05-25
Last updated on: 2026-05-25
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tiandy | easy7_integrated_management_platform | 7.17.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-640 | The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Tiandy Easy7 Integrated Management Platform version 7.17.0, specifically in the API endpoint that processes the file /rest/user/updateUserPassword. The issue allows an attacker to manipulate the password recovery process, resulting in weak password recovery mechanisms. This vulnerability can be exploited remotely.
How can this vulnerability impact me? :
The vulnerability can lead to weak password recovery, which may allow unauthorized attackers to reset or recover user passwords without proper authorization. This could result in unauthorized access to user accounts or systems managed by the Tiandy Easy7 platform.