Impact
The vulnerability resides in Shibby Tomato firmware version 1.28.0000, in the ‘start_6rd_tunnel’ function of the /sbin/rc file accessed via the Web UI. By supplying a crafted value for the ipv6_6rd_borderrelay argument, an unauthenticated remote attacker can cause the router to execute arbitrary shell commands. This results in remote code execution and full compromise of the device. The flaw is a classic OS command injection (CWE‑77/CWE‑78).
Affected Systems
Affected products are devices running Shibby Tomato 1.28.0000 firmware. The vulnerability is specific to the Web UI component that calls the 6rd_tunnel startup routine. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity for this flaw. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The description states the exploit is public and can be launched remotely, implying a convenient attack surface and a high likelihood of exploitation in the wild.
OpenCVE Enrichment