CVE-2026-2944Disclosure(tosei-corporation / online_store_management_system)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file /cgi-bin/monitor.php of the component HTTP POST Request Handler. Performing a manipulation of the argument DevId results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • online_store_management_system

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-22); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
online_store_management_system

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-22: 1Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1PoC Mentioned / Linked · 2026-02-25: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-27: 102-2202-2502-27
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-221
Disclosure1
2026-02-251
PoC1
2026-02-271
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2944 Remote OS Command Injection in Tosei Online Store Management System 1.01 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2944

    Post summary

    A new remote OS command injection vulnerability (CVE-2026-2944) has been identified in Tosei Online Store Management System 1.01, with details available on Vulmon.

    0001075
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2944 (CVSS:6.9, HIGH) is Analyzed. A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function s..https://nvd.nist.gov/vuln/detail/CVE-2026-2944 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet discloses the discovery of CVE-2026-2944, a high‑severity flaw in Tosei Online Store Management System 1.01, providing basic CVSS information but no details on exploitation, patches, or PoC.

    0000018
    173 followersView on X
  • Cybersecurity Aide@SecAideInfo
    PoC

    🚨#CyberAlert: A critical security flaw (CVE-2026-2944) in Tosei Online Store Management (v1.01) could lead to OS command injection via /cgi-bin/monitor.php! ⚠️ Exploit is public, and attacks could be imminent. No vendor response yet. Stay vigilant! 🔒 #CyberSecurity #Infosec

    Post summary

    CVE-2026-2944 is a critical OS command injection flaw in Tosei Online Store Management v1.01, with a public exploit available and potential imminent attacks, but no vendor patch yet.

    0000045
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptosei-corporationonline_store_management_system1.01--

Explore more