{"id":"CVE-2026-71237","published":"2026-08-05T11:16:26.503","lastModified":"2026-08-10T12:17:26.197","description":"Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query(\"select * from userlists where username='' and password='' limit 1\"). An unauthenticated attacker can submit a payload such as pwd=' OR '1'='1 to bypass authentication and, via UNION-based injection, extract arbitrary data from the database.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Miantang/IoT-PHP","tags":[]}],"exploitRefs":[{"url":"https://github.com/Miantang/IoT-PHP","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an unauthenticated attacker to bypass authentication and potentially extract database data via SQL injection, posing a critical security risk.","exploitability":"Exploitation is relatively easy as it requires submitting a specific payload to the /userlogin endpoint, making it a significant threat.","blast_radius":"If exploited, the attacker could gain full access to the database, leading to data breaches and potential system compromise.","remediation":"Disable the affected /userlogin endpoint or apply a patch to sanitize user input and prevent SQL injection, such as upgrading to the latest version of the software.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","sql-injection","web","rce"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:00:38.102Z"}}