Tiandy Easy7 Integrated Management Platform OS Command Injection Vulnerability

Vulnerability

An OS command injection vulnerability has been identified in Tiandy Easy7 Integrated Management Platform version 7.17.0. The issue arises in the file '/Easy7/rest/systemInfo/updateDbBackupInfo', where manipulation of the 'week' parameter allows for command injection. This vulnerability can be exploited remotely, and the exploit is publicly available.

Impact

Exploitation of this vulnerability allows for OS command injection, where an attacker can execute arbitrary commands on the server.

Reproduction

To reproduce this vulnerability, send a POST request to '/Easy7/rest/systemInfo/updateDbBackupInfo' with the 'week' parameter manipulated to include a command injection payload. The injected command will be executed on the server, and the output can be directed to a file in the root directory.

Added: May 3, 2026, 2:18 PM
Updated: May 3, 2026, 2:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
7.2
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.