CVE-2026-4585
A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/ImportSystemConfiguration.jsp of the component Configuration Handler. The manipulation of the argument File leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 4.47%
- CWE
- CWE-78, CWE-77
- Published
- 2026-03-23
- Last modified
- 2026-03-23
Affected products
- Tiandy Easy7 Integrated Management Platform
- Tiandy Easy7 Integrated Management Platform
- Tiandy Easy7 Integrated Management Platform
- Tiandy Easy7 Integrated Management Platform
- Tiandy Easy7 Integrated Management Platform
- Tiandy Easy7 Integrated Management Platform
- Tiandy Easy7 Integrated Management Platform
- Tiandy Easy7 Integrated Management Platform
Weakness type
Related vulnerabilities
- CVE-2026-87911 — Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server
- CVE-2026-77120 — CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
- CVE-2026-70425 — Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and...
- CVE-2026-23855 — Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell...
- CVE-2026-79689 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79641 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87088 — Tanium addressed an unauthorized code execution vulnerability in Enforce.
- CVE-2026-78630 — Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing