Junglewise Threat Intelligence

CVE-2026-9465: Tiandy Easy7 Integrated Management Platform SQL injection in GetDBDataEx.jsp

CVE-2026-9465 · Severity: high · CVSS 7.3 · Published 2026-05-25

Executive brief

Tiandy Easy7 Integrated Management Platform, a centralized system used for managing security surveillance and video monitoring, contains a security flaw that allows unauthorized individuals to manipulate database queries. By sending a specially crafted web request, an attacker could potentially access, modify, or delete sensitive information stored within the platform's database. This could lead to a loss of data integrity or unauthorized access to surveillance records and system configurations.

Technical details

A SQL injection vulnerability exists in the Tiandy Easy7 Integrated Management Platform version 7.17.0. The flaw is located within the /Easy7/apps/WebService/GetDBDataEx.jsp component and stems from improper neutralization of the 'strTBName' argument. A remote, unauthenticated attacker can exploit this by sending a malicious HTTP request to the vulnerable endpoint, allowing for the execution of arbitrary SQL commands. This can result in unauthorized data retrieval, modification, or deletion. Public exploit code is reportedly available, and the vendor has not yet provided a patch or official response.

Affected products

  • Tiandy Easy7 Integrated Management Platform 7.17.0

Timeline

  • 2026-05-25: advisory: Vulnerability published by VulDB/NVD
  • 2026-05-25: disclosed: Public exploit made available

References

Related threats