{"id":"CVE-2026-71231","published":"2026-08-05T11:16:25.740","lastModified":"2026-08-10T12:17:25.533","description":"IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding with no sanitization of the decoded value before it is concatenated into the SQL string.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://github.com/thebradleysanders/IOTSmartHome","tags":[]}],"exploitRefs":[{"url":"https://github.com/thebradleysanders/IOTSmartHome","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to execute arbitrary SQL commands by injecting malicious input into the decoded cookie value, leading to potential unauthorized access to user data.","exploitability":"Exploitation is relatively straightforward given the lack of input validation, making it a high-risk vulnerability.","blast_radius":"If exploited, the attacker could gain full control over user accounts, leading to data breaches and potential misuse of the affected IoT device.","remediation":"Upgrade to the latest version of IOTSmartHome, specifically version 2.590 or later, which includes the necessary security patches.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","sql-injection","web","auth-bypass"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:00:44.281Z"}}