Impact
The vulnerability resides in Shibby Tomato, where user‑controlled inputs for the cifs1/cifs2 arguments are insufficiently sanitized, allowing an attacker to inject and execute operating‑system commands. This flaw is aligned with CWE-77 and CWE-78. If exploited, an attacker could execute arbitrary OS commands on the device, potentially affecting the device’s functionality. (Based on the description, it is inferred that the command injection could lead to such impact.)
Affected Systems
Shibby Tomato versions up to 1.28.0000 are affected. The issue is tied to the sub_2D048 function in the CIFS Mount component. No other vendor or product variants are listed, and the product is superseded by FreshTomato.
Risk and Exploitability
The CVSS indicates moderate severity. The EPSS score of 1% suggests a low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attacker needs remote access to manipulate the cifs1/cifs2 arguments, which can be done over the network. (Inferred: the requirement for remote access is based on the description stating 'The attack can be executed remotely.')
OpenCVE Enrichment