OS Command Injection in Shibby Tomato Router Firmware
CVE-2026-19034
Key Information:
Badges
What is CVE-2026-19034?
A significant vulnerability exists in Shibby Tomato 1.28.0000 within the function new_qoslimit_stop located in /tmp/qoslimittc_stop.sh. This flaw allows attackers to manipulate the wan_iface argument, potentially leading to unauthorized execution of operating system commands. An attacker can launch this exploit remotely, opening the door for possible unauthorized access and system compromise. The vulnerability has been publicly disclosed and poses a significant security risk, especially since this version is superseded by FreshTomato, indicating the urgency for users to migrate to a more secure alternative.
Affected Version(s)
Tomato 1.28.0000
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
