← Back to search

CVE-2026-71231

9.8 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw allows an attacker to execute arbitrary SQL commands by injecting malicious input into the decoded cookie value, leading to potential unauthorized access to user data.
Exploitability
Exploitation is relatively straightforward given the lack of input validation, making it a high-risk vulnerability.
Blast radius
If exploited, the attacker could gain full control over user accounts, leading to data breaches and potential misuse of the affected IoT device.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of IOTSmartHome, specifically version 2.590 or later, which includes the necessary security patches.
rcesql-injectionwebauth-bypass

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding with no sanitization of the decoded value before it is concatenated into the SQL string.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.