CVE-2026-4287Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/queryResources of the component Endpoint. Performing a manipulation of the argument areaId results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-17: 5Technical Details · 2026-03-17: 303-17
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4287 - Tiandy - Easy7 Integrated Management Platform - https://www.redpacketsecurity.com/cve-alert-cve-2026-4287-tiandy-easy7-integrated-management-platform/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4287 #tiandy #easy7-integrated-management-platform

    Post summary

    The post references CVE-2026-4287 and links to a security advisory but provides no specific exploitation or mitigation details.

    0000068
    3.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4287 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4287 #CVE-2026-4287 #CVE #High  #CyberSecurity #InfoSec https://t.co/49owWfrMau

    Post summary

    The tweet announces a new CVE (CVE‑2026‑4287) with a severity of 7.3, highlighting its high risk and broad product impact, but provides no PoC, exploit code, exploitation evidence, or patch details.

    0000046
    101 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4287 A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/query… https://www.cve.org/CVERecord?id=CVE-2026-4287

    Post summary

    The post announces the discovery of CVE-2026-4287 in Tiandy Easy7 7.17.0, noting an affected function in /rest/devStatus/query, but provides no further technical details or remediation information.

    0000082
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4287 - Tiandy Easy7 Integrated Management Platform Endpoint queryResources sql injection Intel Report: https://ift.tt/9ublg8A

    Post summary

    The alert reports CVE-2026-4287 as a SQL injection vulnerability in Tiandy Easy7's endpoint queryResources function, but does not provide a PoC, exploit, or patch information.

    0000041
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4287 SQL Injection in Tiandy Easy7 Integrated Management Platform 7.17.0 via /rest/devStatus/queryResources https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4287

    Post summary

    A disclosure of a SQL Injection vulnerability in Tiandy Easy7 7.17.0 was announced, detailing the affected version and endpoint, with no indications of exploitation or patch availability.

    0000039
    4.0K followersView on X

Explore more