PatchSiren cyber security CVE debrief
CVE-2026-9466 Tiandy CVE debrief
A vulnerability in Tiandy Easy7 Integrated Management Platform 7.17.0 allows remote attackers to manipulate the /rest/user/updateUserPassword API endpoint, resulting in weak password recovery. The issue was published on 2026-05-25 and modified on 2026-05-26. The vendor was contacted but did not respond. The exploit has been publicly disclosed and may be utilized. CVSS 4.0 score: 5.5 (MEDIUM). CWE-640: Weak Password Recovery Mechanism for Forgotten Password.
- Vendor
- Tiandy
- Product
- Easy7 Integrated Management Platform
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-25
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-25
- Advisory updated
- 2026-05-26
Who should care
Organizations using Tiandy Easy7 Integrated Management Platform 7.17.0 for security or building management; security teams responsible for API endpoint protection; administrators managing remote access to integrated management platforms
Technical summary
The Tiandy Easy7 Integrated Management Platform 7.17.0 contains a weak password recovery vulnerability in the /rest/user/updateUserPassword API endpoint. Remote attackers can manipulate this endpoint to compromise password recovery mechanisms. The vulnerability is classified as CWE-640 and has a CVSS 4.0 score of 5.5 (MEDIUM). The exploit has been publicly disclosed.
Defensive priority
medium
Recommended defensive actions
- Review and strengthen password recovery mechanisms in Tiandy Easy7 Integrated Management Platform 7.17.0, specifically the /rest/user/updateUserPassword API endpoint
- Implement multi-factor authentication for password reset operations
- Monitor for unauthorized password change attempts on affected systems
- Contact Tiandy for security patch availability and apply updates when released
- Consider network segmentation to limit exposure of the management platform API endpoints
Evidence notes
Vulnerability affects Tiandy Easy7 Integrated Management Platform 7.17.0. Attack vector is network-based with low attack complexity. The weakness is categorized as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password). Vendor contact was attempted without response.
Official resources
public