Critical Alert 3 Active Exploits Detected Today

CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability →
CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability →
CVE-2026-9198 IBM Langflow Code Injection Vulnerability →
Powered by CVE Watchtower
×
August 5, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-71237NVD

Vulnerability Summary

Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from $_POST['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query("select * from userlists where username='$username' and password='$password' limit 1"). The username value is passed through htmlspecialchars(), which does not encode single quotes by default and therefore does not prevent SQL injection through the password field. An unauthenticated attacker can submit a payload such as pwd=' OR '1'='1 to bypass authentication and, via UNION-based injection, extract arbitrary data from the database.
Severity Level
CRITICAL(9.8)
Published Date
Aug 5, 2026
Last Modified
Aug 5, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
Improper neutralization of special elements used in an SQL command, allowing attackers to modify queries.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh