


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage of the compo…
Published:
15 maart 2026 om 23:00:00
Alert date:
16 maart 2026 om 16:21:26
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
A critical vulnerability (CVE-2026-4221) was discovered in Tiandy Easy7 Integrated Management Platform version 7.17.0. The vulnerability affects the /rest/file/uploadLedImage endpoint and allows unrestricted file upload through manipulation of the File argument. This flaw can be exploited remotely and the exploit has been made publicly available. The vendor was notified about the disclosure but did not respond. The vulnerability poses significant security risks as it allows attackers to upload malicious files without proper restrictions.
Technical details
Mitigation steps:
Affected products:
Tiandy Easy7 Integrated Management Platform
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4221
https://my.feishu.cn/docx/Z5HJdLCxioFs4sxyILbcoSIAnTh?from=from_copylink
https://vuldb.com/?ctiid.351145
https://vuldb.com/?id.351145
https://vuldb.com/?submit.770534
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
