PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9466 Tiandy CVE debrief

A vulnerability in Tiandy Easy7 Integrated Management Platform 7.17.0 allows remote attackers to manipulate the /rest/user/updateUserPassword API endpoint, resulting in weak password recovery. The issue was published on 2026-05-25 and modified on 2026-05-26. The vendor was contacted but did not respond. The exploit has been publicly disclosed and may be utilized. CVSS 4.0 score: 5.5 (MEDIUM). CWE-640: Weak Password Recovery Mechanism for Forgotten Password.

Vendor
Tiandy
Product
Easy7 Integrated Management Platform
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-25
Original CVE updated
2026-05-26
Advisory published
2026-05-25
Advisory updated
2026-05-26

Who should care

Organizations using Tiandy Easy7 Integrated Management Platform 7.17.0 for security or building management; security teams responsible for API endpoint protection; administrators managing remote access to integrated management platforms

Technical summary

The Tiandy Easy7 Integrated Management Platform 7.17.0 contains a weak password recovery vulnerability in the /rest/user/updateUserPassword API endpoint. Remote attackers can manipulate this endpoint to compromise password recovery mechanisms. The vulnerability is classified as CWE-640 and has a CVSS 4.0 score of 5.5 (MEDIUM). The exploit has been publicly disclosed.

Defensive priority

medium

Recommended defensive actions

  • Review and strengthen password recovery mechanisms in Tiandy Easy7 Integrated Management Platform 7.17.0, specifically the /rest/user/updateUserPassword API endpoint
  • Implement multi-factor authentication for password reset operations
  • Monitor for unauthorized password change attempts on affected systems
  • Contact Tiandy for security patch availability and apply updates when released
  • Consider network segmentation to limit exposure of the management platform API endpoints

Evidence notes

Vulnerability affects Tiandy Easy7 Integrated Management Platform 7.17.0. Attack vector is network-based with low attack complexity. The weakness is categorized as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password). Vendor contact was attempted without response.

Official resources

public