CVE-2026-71231: Thebradleysanders Iotsmarthome

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding with no sanitization of the decoded value before it is concatenated into the SQL string.

Affected products

Published 2026-08-05. Last modified 2026-08-26.