A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of the file /Easy7/rest/systemInfo/updateDbBackupInfo. Such manipulation of the argument week leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-7698 is a remote OS command injection vulnerability in Tiandy Easy7 Integrated Management Platform 7.17.0 affecting the /Easy7/rest/systemInfo/updateDbBackupInfo endpoint through the week parameter. The vulnerability has a CVSS score of 7.3 and public exploits are available, posing significant risk to organizations using this platform.
تؤثر هذه الثغرة على منصة Tiandy Easy7 الإصدار 7.17.0 حيث يمكن لمهاجم بعيد تنفيذ أوامر نظام التشغيل عبر معامل week في وظيفة updateDbBackupInfo. الثغرة لم يتم إصلاحها من قبل البائع رغم التواصل المبكر معه.
A remote OS command injection vulnerability exists in Tiandy Easy7 Platform 7.17.0 where the week parameter in /Easy7/rest/systemInfo/updateDbBackupInfo allows attackers to execute arbitrary commands. This high-severity flaw (CVSS 7.3) has public exploits and affects database backup functionality.
Immediately update Tiandy Easy7 to a patched version beyond 7.17.0. Implement network segmentation to restrict access to the /Easy7/rest/systemInfo endpoint. Deploy Web Application Firewall (WAF) rules to filter malicious week parameter inputs. Monitor logs for suspicious updateDbBackupInfo requests. Disable the endpoint if not required for operations.
قم بتحديث منصة Tiandy Easy7 فوراً إلى إصدار مصحح أحدث من 7.17.0. طبق تقسيم الشبكة لتقييد الوصول إلى نقطة نهاية /Easy7/rest/systemInfo. استخدم جدار حماية تطبيقات الويب لتصفية مدخلات معاملات week الضارة. راقب السجلات للطلبات المريبة. عطل نقطة النهاية إذا لم تكن مطلوبة.