Vulnerabilidad · Publicado 06/08/2026
Se identificó una vulnerabilidad de inyección de comandos en Shibby Tomato 1.28.0000 que afecta la función new_qoslimit_stop en /tmp/qoslimittc_stop.sh. Un atacante remoto puede manipular el parámetro wan_iface para ejecutar comandos del sistema operativo con privilegios del dispositivo. El exploit es público y activamente utilizado. Nota: Este proyecto ha sido descontinuado en favor de FreshTomato.
A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.
Score: 7.2/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-77, CWE-78
Publicado en NIST NVD.