๐Ÿ” CVE Alert

CVE-2026-71231

CRITICAL 9.8

IOTSmartHome: Unauthenticated SQL Injection via lastLogin Cookie

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode(), which performs URL-safe base64 decoding with no sanitization of the decoded value before it is concatenated into the SQL string. An unauthenticated attacker can set a lastLogin cookie containing a base64-encoded SQL injection payload (e.g. base64("' OR '1'='1")) to bypass authentication and, via UNION-based injection, extract arbitrary data including user credentials.

CWE CWE-89
Vendor thebradleysanders
Product iotsmarthome
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for thebradleysanders iotsmarthome

Be the first to know when new critical vulnerabilities affecting thebradleysanders iotsmarthome are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

thebradleysanders / IOTSmartHome
0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/thebradleysanders/IOTSmartHome

Credits

Mirdavlatov Mira'zam