Tosei Self-Service Washing Machine Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Tosei Self-Service Washing Machine version 4.02. The issue arises in the file '/cgi-bin/tosei_datasend.php', where the 'adr_txt_1' argument can be manipulated to execute arbitrary commands. This vulnerability can be exploited remotely without authentication.

Impact

Exploitation of this vulnerability allows for remote command execution on the affected washing machine.

Reproduction

To reproduce this vulnerability, send a GET request to '/cgi-bin/tosei_datasend.php' with the 'adr_txt_1' parameter set to a crafted value that includes command injection payloads. The request can be made using a web browser or a tool like curl, and should include the necessary headers such as 'Authorization' for basic authentication.

Added: Feb 16, 2026, 4:24 AM
Updated: Feb 16, 2026, 4:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
2.9
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.