Impact
Affected input parameter DevId of the /cgi-bin/imode_alldata.php script allows remote attackers to inject arbitrary shell commands. The flaw is a classic command injection (CWE‑74) combined with insufficient input sanitization (CWE‑77), enabling the execution of system commands in the server's context. Successful exploitation would compromise the confidentiality, integrity, and availability of the application and potentially the underlying server.
Affected Systems
Vulnerability is present in Tosei Online Store Management System ネット店舗管理システム 1.01 from the vendor Tosei. No other affected versions or hosts are listed. The issue resides in the system's web interface, specifically the imode_alldata.php CGI component.
Risk and Exploitability
The CVSS score of 6.9 indicates substantial impact, while an EPSS of 3% shows a moderate probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, yet it can be exploited remotely by crafting a malicious DevId value over HTTP. The lack of vendor response underscores the need for immediate mitigation.
OpenCVE Enrichment