SQL Injection Vulnerability in Miantang IoT-PHP Product
CVE-2026-71237

9.8CRITICAL

Key Information:

Vendor

Miantang

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71237?

The IoT-PHP product from Miantang contains a significant security flaw in its index.php where user credentials are processed without adequate sanitization. Specifically, during the user login process, the application directly integrates user-provided passwords into SQL queries. This exposes the system to SQL injection attacks, whereby an unauthenticated attacker can craft malicious input to bypass authentication and potentially extract sensitive data from the database using UNION-based injection techniques.

Affected Version(s)

IoT-PHP 0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mirdavlatov Mira'zam
.