Tiandy manufactures video surveillance and camera products, including IP cameras and content management systems, where its disclosed vulnerabilities cluster around information exposure, access control, and injection-class weaknesses spanning SQL injection, output injection, and dangerous file uploads. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tiandy over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15236HIGH Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted request to TCP port 3001, as dem | Oct 11, 2017 | 7.5 | 34 | NO | YES |
CVE-2026-3818CRITICAL A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This manipulation of the argument strTBN | Mar 9, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-3797HIGH A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile of the file /src/com/tiandy/easy7/core | Mar 9, 2026 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tiandy.
Media articles that mention a CVE ID that affects a product developed by Tiandy — matched by CVE ID, not by vendor name.