Impact
This vulnerability arises from a permissive regular expression in Tegalog -Fumy Otegaru Memo Logger, allowing an attacker who can reach the application to authenticate to the management console. The attacker can then perform any operations granted to a console user, effectively gaining full administrative capabilities over the system. The weakness is a classic improper validation flaw (CWE-625).
Affected Systems
The product affected is Tegalog -Fumy Otegaru Memo Logger provided by Nishishi Factory. No specific version information is disclosed, so all current installations potentially remain vulnerable until updated.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. EPSS data is unavailable, so no clear estimate of current exploit likelihood is present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or remote access to the application, as it requires the attacker to reach the product to exploit the regex. Once authenticated, the attacker can leverage full console privileges, leading to complete compromise of the managed system.
OpenCVE Enrichment