TopVuln

High-risk vulnerability digests

CVE-2026-4585

  • HIGH

Details

CVSS v3
9.8
CVSS v4
8.9
CVSS v2
10.0
NVD published
2026-03-23 12:16:25
Affected versions
Tiandy Easy7 Integrated Management Platform up to 7.17.0
Summary
This vulnerability allows remote attackers to inject arbitrary operating system commands via the configuration upload handler of the platform. The exploit has been publicly disclosed, and the vendor has not responded to vulnerability reports. Successful exploitation leads to full remote compromise of the management platform.
Remediation
Isolate the affected Tiandy Easy7 platform from public networks until an official patch is released. Replace the unsupported platform with a maintained alternative if no patch is made available.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.