Published:2026/07/29  Last Updated:2026/07/29

JVN#99975039
Permissive regular expression vulnerability in Tegalog -Fumy Otegaru Memo Logger-

Overview

Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression.

Products Affected

  • Tegalog -Fumy Otegaru Memo Logger- Ver 4.8.4 and earlier.

Description

Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains the following vulnerability:

  • Permissive Regular Expression (CWE-625)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N Base Score 8.8
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L Base Score 8.6
    • CVE-2026-64940

Impact

An attacker who can access the affected product may log in to the management console. As a result, the attacker may perform any operations available from the management console.

Solution

Update the CGI
Apply the latest update according to the information provided by the developer.

Vendor Status

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Yuji Tounai of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-64940
JVN iPedia JVNDB-2026-000104