Description
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
Published: 2026-08-10
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from a permissive regular expression in Tegalog -Fumy Otegaru Memo Logger, allowing an attacker who can reach the application to authenticate to the management console. The attacker can then perform any operations granted to a console user, effectively gaining full administrative capabilities over the system. The weakness is a classic improper validation flaw (CWE-625).

Affected Systems

The product affected is Tegalog -Fumy Otegaru Memo Logger provided by Nishishi Factory. No specific version information is disclosed, so all current installations potentially remain vulnerable until updated.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. EPSS data is unavailable, so no clear estimate of current exploit likelihood is present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or remote access to the application, as it requires the attacker to reach the product to exploit the regex. Once authenticated, the attacker can leverage full console privileges, leading to complete compromise of the managed system.

Generated by OpenCVE AI on August 10, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Tegalog -Fumy Otegaru Memo Logger to the latest vendor‑supplied version or apply the vendor‑issued patch, if available.
  • Configure the management console to require multifactor authentication and restrict access to trusted networks.
  • Implement strict login attempt limits and monitor authentication logs for suspicious activity.

Generated by OpenCVE AI on August 10, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Permissive Regular Expression Enabling Management Console Login in Tegalog -Fumy Otegaru Memo Logger

Mon, 10 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
Weaknesses CWE-625
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-10T07:09:50.899Z

Reserved: 2026-07-27T06:27:45.155Z

Link: CVE-2026-64940

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T08:30:04Z

Weaknesses
  • CWE-625

    Permissive Regular Expression