Impact
The flaw resides in the start_jffs2 component of Shibby Tomato firmware, specifically in the sub_2D568 routine. Manipulating the jffs2_exec argument triggers an OS command injection that allows an attacker to execute arbitrary commands on the device, compromising its affected Tomato firmware versions up to 1.28.0000. The vulnerability is tied to the start_jffs2 handler used during system configuration and upgrade processes, and the project is superseded by FreshTomato.
Affected Systems
The vendor Shibby, product Tomato, versions up to 1.28.0000 are affected by this command injection flaw.
Risk and Exploitability
The CVSS base score of 5.3 indicates medium severity, and the EPSS score of 1% reflects a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that remote exploitation is possible via a network interface that accepts the jffs2_exec parameter; once the injection succeeds, an attacker can run arbitrary commands. Publicly available exploit code raises the practical risk for exposed devices.
OpenCVE Enrichment