
⚠️⚠️ CVE-2026-36537 (CVSS 9.8): OAuth authorization code exchange auth bypass in ThingsBoard v4.3.0.1. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJUaGluZ3NCb2FyZCI%3D 🎯14K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="ThingsBoard" 🔖Refer: https://nvd.nist.gov/vuln/detail/CVE-2026-36537 #OSINT #FOFA #CyberSecurity #Vulnerability
Post summary
This post announces the CVE‑2026‑36537 (OAuth authorization code exchange auth bypass in ThingsBoard v4.3.0.1) and shares FOFA search results showing many potential affected instances, but it provides no evidence of exploitation, a PoC, or a patch.
