CVE-2026-71231: Thebradleysanders Iotsmarthome
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding with no sanitization of the decoded value before it is concatenated into the SQL string.
Affected products
- Thebradleysanders Iotsmarthome: version 0 only
Published 2026-08-05. Last modified 2026-08-26.