Description
A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unknown function of the file /cgi-bin/imode_alldata.php. Executing a manipulation of the argument DevId can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-01-19
Score: 6.9 Medium
EPSS: 2.6% Low
KEV: No
Impact: Remote command execution
Action: Apply patch
AI Analysis

Impact

Affected input parameter DevId of the /cgi-bin/imode_alldata.php script allows remote attackers to inject arbitrary shell commands. The flaw is a classic command injection (CWE‑74) combined with insufficient input sanitization (CWE‑77), enabling the execution of system commands in the server's context. Successful exploitation would compromise the confidentiality, integrity, and availability of the application and potentially the underlying server.

Affected Systems

Vulnerability is present in Tosei Online Store Management System ネット店舗管理システム 1.01 from the vendor Tosei. No other affected versions or hosts are listed. The issue resides in the system's web interface, specifically the imode_alldata.php CGI component.

Risk and Exploitability

The CVSS score of 6.9 indicates substantial impact, while an EPSS of 3% shows a moderate probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, yet it can be exploited remotely by crafting a malicious DevId value over HTTP. The lack of vendor response underscores the need for immediate mitigation.

Generated by OpenCVE AI on April 18, 2026 at 04:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Tosei Online Store Management System 1.01 or later.
  • If no patch is available, restrict external access to /cgi-bin/imode_alldata.php to trusted IP ranges or protect the endpoint with a Web Application Firewall rule that blocks command injection patterns.
  • Ensure that the DevId parameter is validated and sanitized to remove shell metacharacters before being used in system calls; consider using a whitelist of expected numeric values.

Generated by OpenCVE AI on April 18, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tosei-corporation
Tosei-corporation online Store Management System
CPEs cpe:2.3:a:tosei-corporation:online_store_management_system:1.01:*:*:*:*:*:*:*
Vendors & Products Tosei-corporation
Tosei-corporation online Store Management System

Wed, 21 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Tosei
Tosei online Store Management System
Vendors & Products Tosei
Tosei online Store Management System

Mon, 19 Jan 2026 23:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unknown function of the file /cgi-bin/imode_alldata.php. Executing a manipulation of the argument DevId can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Tosei Online Store Management System ネット店舗管理システム imode_alldata.php command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tosei Online Store Management System
Tosei-corporation Online Store Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:50:22.457Z

Reserved: 2026-01-19T13:49:11.930Z

Link: CVE-2026-1192

cve-icon Vulnrichment

Updated: 2026-01-21T19:48:00.441Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-19T23:16:03.067

Modified: 2026-02-26T20:45:46.907

Link: CVE-2026-1192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T05:00:06Z

Weaknesses