Tosei · Tosei Self-Service Washing Machine · CVE-2026-2533
**Name of the Vulnerable Software and Affected Versions**
Tosei Self-service Washing Machine version 4.02
**Description**
A flaw exists in Tosei Self-service Washing Machine version 4.02. The issue impacts an unknown function within the `/cgi-bin/tosei datasend.php` file. Manipulation of the `adr txt 1` argument can lead to command injection, allowing for remote attacks. The exploit for this issue has been published. The vendor was contacted regarding this disclosure but did not respond.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.