What is CVE-2026-71231?
A SQL injection vulnerability was discovered in IOTSmartHome's gui/login.php checkCookie() function. The 'lastLogin' cookie value is used in an SQL query without sanitization, enabling remote code execution. IOTSmartHome users should urgently apply a patch from the vendor.
Azərbaycanca: IOTSmartHome-un gui/login.php faylındakı checkCookie() funksiyasında SQL inyeksiya zəifliyi aşkarlanıb. İstifadəçi tərəfindən göndərilən 'lastLogin' çərəzinin sanitizə olunmadan SQL sorğusunda istifadə edilməsi uzaqdan kod icrasına imkan verir. IOTSmartHome istifadəçiləri təcili olaraq istehsalçıdan yamaq tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which file is the SQL injection vulnerability in IOTSmartHome located?
The vulnerability is located in the checkCookie() function within the gui/login.php file.
How can I protect against this SQL injection attack?
You should urgently apply the security patch provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.