Published:2026/01/16  Last Updated:2026/01/16

JVN#08087148
Multiple Vulnerabilities in TOA Network Cameras TRIFORA 3 series

Overview

Network Cameras TRIFORA 3 series provided by TOA Corporation contain multiple vulnerabilities.

Products Affected

A wide range of products and versions are affected. For more information, refer to "Vendor Status" section below.

Description

Network Cameras TRIFORA 3 series provided by TOA Corporation contain multiple vulnerabilities listed below.

  • OS command injection (CWE-78)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.8
    • CVE-2026-20759
  • Cross-site scripting (CWE-79)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 4.8
    • CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N Base Score 4.8
    • CVE-2026-20894
  • Path traversal (CWE-22)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 7.1
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Base Score 6.5
    • CVE-2026-22876

Impact

  • A logged-in user with the low("monitoring user") or higher privilege may execute an arbitrary OS command. (CVE-2026-20759)
  • If an attacking administrator configures the affected product with some malicious input, an arbitrary script may be executed on the web browser of a victim administrator who accesses the setting screen. (CVE-2026-20894)
  • Arbitrary files on the affected product may be retrieved by a logged-in user with the low("monitoring user") or higher privilege. (CVE-2026-22876)

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
TOA Corporation Vulnerable 2026/01/16 TOA Corporation website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Shogo Iyota of GMO Cybersecurity by Ierae reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-20759
CVE-2026-20894
CVE-2026-22876
JVN iPedia JVNDB-2026-000007