Tosei · Online Store Management System ネット店舗管理システム · CVE-2026-1192
**Name of the Vulnerable Software and Affected Versions**
Tosei Online Store Management System version 1.01
**Description**
An unknown function within the '/cgi-bin/imode alldata.php' endpoint allows remote command injection. This occurs when the `DevId` argument is manipulated, enabling an attacker to execute arbitrary commands on the system.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.